Lucene search

K
prionPRIOn knowledge basePRION:CVE-2016-6210
HistoryFeb 13, 2017 - 5:59 p.m.

Design/Logic Flaw

2017-02-1317:59:00
PRIOn knowledge base
www.prio-n.com
55

7.1 High

AI Score

Confidence

Low

0.107 Low

EPSS

Percentile

95.1%

sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.

CPENameOperatorVersion
opensshle7.2