Lucene search

K
nvd[email protected]NVD:CVE-2007-2243
HistoryApr 25, 2007 - 4:19 p.m.

CVE-2007-2243

2007-04-2516:19:00
CWE-287
web.nvd.nist.gov
6

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.007

Percentile

80.7%

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.

Affected configurations

Nvd
Node
openbsdopensshMatch1.2
OR
openbsdopensshMatch1.2.1
OR
openbsdopensshMatch1.2.2
OR
openbsdopensshMatch1.2.3
OR
openbsdopensshMatch1.2.27
OR
openbsdopensshMatch2.1
OR
openbsdopensshMatch2.1.1
OR
openbsdopensshMatch2.2
OR
openbsdopensshMatch2.3
OR
openbsdopensshMatch2.5
OR
openbsdopensshMatch2.5.1
OR
openbsdopensshMatch2.5.2
OR
openbsdopensshMatch2.9
OR
openbsdopensshMatch2.9.9
OR
openbsdopensshMatch2.9.9p2
OR
openbsdopensshMatch2.9p1
OR
openbsdopensshMatch2.9p2
OR
openbsdopensshMatch3.0
OR
openbsdopensshMatch3.0.1
OR
openbsdopensshMatch3.0.1p1
OR
openbsdopensshMatch3.0.2
OR
openbsdopensshMatch3.0.2p1
OR
openbsdopensshMatch3.0p1
OR
openbsdopensshMatch3.1
OR
openbsdopensshMatch3.1p1
OR
openbsdopensshMatch3.2
OR
openbsdopensshMatch3.2.2
OR
openbsdopensshMatch3.2.2p1
OR
openbsdopensshMatch3.2.3p1
OR
openbsdopensshMatch3.3
OR
openbsdopensshMatch3.3p1
OR
openbsdopensshMatch3.4
OR
openbsdopensshMatch3.4p1
OR
openbsdopensshMatch3.5
OR
openbsdopensshMatch3.5p1
OR
openbsdopensshMatch3.6
OR
openbsdopensshMatch3.6.1
OR
openbsdopensshMatch3.6.1p1
OR
openbsdopensshMatch3.6.1p2
OR
openbsdopensshMatch3.7
OR
openbsdopensshMatch3.7.1
OR
openbsdopensshMatch3.7.1p1
OR
openbsdopensshMatch3.7.1p2
OR
openbsdopensshMatch3.8
OR
openbsdopensshMatch3.8.1
OR
openbsdopensshMatch3.8.1p1
OR
openbsdopensshMatch3.9
OR
openbsdopensshMatch3.9.1
OR
openbsdopensshMatch3.9.1p1
OR
openbsdopensshMatch4.0
OR
openbsdopensshMatch4.0p1
OR
openbsdopensshMatch4.1
OR
openbsdopensshMatch4.1p1
OR
openbsdopensshMatch4.2
OR
openbsdopensshMatch4.2p1
OR
openbsdopensshMatch4.3
OR
openbsdopensshMatch4.3p1
OR
openbsdopensshMatch4.3p2
OR
openbsdopensshMatch4.4
OR
openbsdopensshMatch4.4p1
OR
openbsdopensshMatch4.5
OR
openbsdopensshMatch4.6
VendorProductVersionCPE
openbsdopenssh1.2cpe:2.3:a:openbsd:openssh:1.2:*:*:*:*:*:*:*
openbsdopenssh1.2.1cpe:2.3:a:openbsd:openssh:1.2.1:*:*:*:*:*:*:*
openbsdopenssh1.2.2cpe:2.3:a:openbsd:openssh:1.2.2:*:*:*:*:*:*:*
openbsdopenssh1.2.3cpe:2.3:a:openbsd:openssh:1.2.3:*:*:*:*:*:*:*
openbsdopenssh1.2.27cpe:2.3:a:openbsd:openssh:1.2.27:*:*:*:*:*:*:*
openbsdopenssh2.1cpe:2.3:a:openbsd:openssh:2.1:*:*:*:*:*:*:*
openbsdopenssh2.1.1cpe:2.3:a:openbsd:openssh:2.1.1:*:*:*:*:*:*:*
openbsdopenssh2.2cpe:2.3:a:openbsd:openssh:2.2:*:*:*:*:*:*:*
openbsdopenssh2.3cpe:2.3:a:openbsd:openssh:2.3:*:*:*:*:*:*:*
openbsdopenssh2.5cpe:2.3:a:openbsd:openssh:2.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 621

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.007

Percentile

80.7%