sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 6.1 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 7.1 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 7.2 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Alpine Linux | — | Upgrade openssh | Aug 30, 2017 | Feb 13, 2017 |
| Amazon_linux | — | Upgrade openssh | Oct 3, 2017 | Jul 24, 2016 |
| Centos_linux | — | Upgrade openssh-ldapUpgrade openssh-serverUpgrade pam_ssh_agent_authUpgrade openssh-askpassUpgrade opensshUpgrade openssh-server-sysvinitUpgrade openssh-clientsUpgrade openssh-debuginfoUpgrade openssh-keycatUpgrade openssh-cavs | Sep 1, 2017 | Jul 24, 2016 |
| Debian | — | Upgrade openssh | Jul 24, 2016 | Jul 24, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Dec 23, 2016 |
| Freebsd | — | Upgrade openssh-portable | Dec 10, 2025 | Sep 1, 2016 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Feb 13, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade openssh-askpassUpgrade openssh-serverUpgrade opensshUpgrade openssh-clientsUpgrade openssh-keycat | Nov 30, 2017 | Feb 13, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssh-askpassUpgrade openssh-clientsUpgrade opensshUpgrade openssh-keycatUpgrade openssh-server | Nov 30, 2017 | Feb 13, 2017 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory9 | Nov 30, 2017 | Feb 13, 2017 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 7.3 | Mar 13, 2017 | Feb 13, 2017 |
| Oracle Solaris | — | Upgrade system/library to version 0.5.11-0.175.3.28.0.4.0 on Solaris 11.3Upgrade network/openssh to version 7.3.0.1-0.175.3.15.0.2.0 on Solaris 11.3 | May 29, 2017 | Feb 13, 2017 |
| Oracle_linux | — | Upgrade pam_ssh_agent_authUpgrade openssh-ldapUpgrade openssh-keycatUpgrade openssh-server-sysvinitUpgrade openssh-askpassUpgrade openssh-serverUpgrade openssh-clientsUpgrade openssh-cavsUpgrade openssh | Aug 8, 2017 | Jul 14, 2016 |
| Panos | — | Update PAN-OS 7.1 to the latest workaround for your deviceUpgrade PAN-OS 7.0 to the latest versionUpdate PAN-OS 6.0 to the latest workaround for your deviceUpdate PAN-OS 6.1 to the latest workaround for your device | Nov 18, 2016 | Jul 24, 2016 |
| Redhat_linux | — | Upgrade openssh-clientsNo solution existsUpgrade openssh-keycatUpgrade openssh-server-sysvinitUpgrade openssh-cavsUpgrade opensshUpgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-askpassUpgrade openssh-debuginfoUpgrade pam_ssh_agent_auth | Aug 3, 2017 | Jul 24, 2016 |
| Suse | — | Upgrade openssh-openssl1Upgrade openssh-helpersUpgrade openssh-serverUpgrade openssh-askpass-gnomeUpgrade openssh-openssl1-helpersUpgrade openssh-fipsUpgrade openssh-clientsUpgrade opensshUpgrade openssh-commonUpgrade openssh-askpass | Sep 12, 2016 | Jul 24, 2016 |
| Ubuntu | — | Upgrade openssh-server | Aug 17, 2016 | Jul 24, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub