Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attackers to cause a denial of service (connection slot exhaustion) via a large number of connection attempts that exceeds the MAX_UNAUTH_CLIENTS defined value of 30.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dropbear | Jul 30, 2024 | Mar 14, 2006 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.2.0.0.42.2 on Solaris 11.2Upgrade network/ssh to version 0.5.11-0.175.1.7.0.4.2 on Solaris 11.1Upgrade network/ssh/ssh-key to version 0.5.11-0.175.1.7.0.2.2 on Solaris 11.1Upgrade service/network/ssh to version 0.5.11-0.175.1.7.0.4.2 on Solaris 11.1 | May 29, 2017 | Mar 13, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub