The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssh | Jul 30, 2024 | Mar 7, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 15, 2015 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Mar 7, 2013 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Mar 7, 2013 |
| Hpux | — | Update Secure_Shell.SECURE_SHELL to the latest versionUpdate Secure_Shell.SECSH-CMN to the latest version | Aug 11, 2017 | Mar 7, 2013 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory2 | Nov 30, 2017 | Mar 7, 2013 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Mar 18, 2013 | Mar 7, 2013 |
| Oracle Solaris | — | Upgrade network/ssh to version 0.5.11-0.175.1.7.0.4.2 on Solaris 11.1Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4Upgrade service/network/ssh to version 0.5.11-0.175.1.7.0.4.2 on Solaris 11.1Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.2.0.0.42.2 on Solaris 11.2Upgrade network/ssh/ssh-key to version 0.5.11-0.175.1.7.0.2.2 on Solaris 11.1 | May 29, 2017 | Mar 7, 2013 |
| Oracle_linux | — | Upgrade openssh-serverUpgrade openssh-askpassUpgrade opensshUpgrade openssh-clients | Oct 16, 2024 | Mar 7, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 6, 2013 |
| Suse | — | Upgrade openssh-askpassUpgrade openssh-openssl1Upgrade opensshUpgrade openssh-fipsUpgrade openssh-openssl1-helpers | Dec 12, 2013 | Feb 7, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub