Lucene search

K
f5F5F5:K14845276
HistoryDec 23, 2016 - 12:00 a.m.

K14845276 : OpenSSH vulnerability CVE-2016-6210

2016-12-2300:00:00
my.f5.com
33

6.5 Medium

AI Score

Confidence

High

0.107 Low

EPSS

Percentile

95.1%

Security Advisory Description

When SSHD tries to authenticate a non-existing user, it will pick up a fake password structure hard-coded in the SSHD source code. An attacker can measure timing information to determine if a user exists when verifying a password. (CVE-2016-6210)
Impact
This vulnerability allows an attacker to disrupt service.