sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 6.1 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 7.1 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 7.2 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Alpine Linux | — | Upgrade openssh | Aug 30, 2017 | Feb 13, 2017 |
| Amazon_linux | — | Upgrade openssh | Oct 3, 2017 | Jul 24, 2016 |
| Centos_linux | — | Upgrade openssh-server-sysvinitUpgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-cavsUpgrade openssh-debuginfoUpgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh | Sep 1, 2017 | Jul 24, 2016 |
| Debian | — | Upgrade openssh | Jul 24, 2016 | Jul 24, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Dec 23, 2016 |
| Freebsd | — | Upgrade openssh-portable | Dec 10, 2025 | Sep 1, 2016 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Feb 13, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade opensshUpgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-askpassUpgrade openssh-server | Nov 30, 2017 | Feb 13, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade opensshUpgrade openssh-keycatUpgrade openssh-askpassUpgrade openssh-clientsUpgrade openssh-server | Nov 30, 2017 | Feb 13, 2017 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory9 | Nov 30, 2017 | Feb 13, 2017 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 7.3 | Mar 13, 2017 | Feb 13, 2017 |
| Oracle Solaris | — | Upgrade network/openssh to version 7.3.0.1-0.175.3.15.0.2.0 on Solaris 11.3Upgrade system/library to version 0.5.11-0.175.3.28.0.4.0 on Solaris 11.3 | May 29, 2017 | Feb 13, 2017 |
| Oracle_linux | — | Upgrade openssh-serverUpgrade openssh-cavsUpgrade openssh-askpassUpgrade opensshUpgrade openssh-server-sysvinitUpgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-keycatUpgrade openssh-ldap | Aug 8, 2017 | Jul 14, 2016 |
| Panos | — | Update PAN-OS 7.1 to the latest workaround for your deviceUpdate PAN-OS 6.1 to the latest workaround for your deviceUpgrade PAN-OS 7.0 to the latest versionUpdate PAN-OS 6.0 to the latest workaround for your device | Nov 18, 2016 | Jul 24, 2016 |
| Redhat_linux | — | No solution existsUpgrade openssh-server-sysvinitUpgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-ldapUpgrade openssh-cavsUpgrade openssh-debuginfoUpgrade openssh-serverUpgrade openssh-askpassUpgrade opensshUpgrade pam_ssh_agent_auth | Aug 3, 2017 | Jul 24, 2016 |
| Suse | — | Upgrade openssh-commonUpgrade openssh-askpassUpgrade openssh-openssl1-helpersUpgrade openssh-fipsUpgrade openssh-clientsUpgrade opensshUpgrade openssh-askpass-gnomeUpgrade openssh-openssl1Upgrade openssh-serverUpgrade openssh-helpers | Sep 12, 2016 | Jul 24, 2016 |
| Ubuntu | — | Upgrade openssh-server | Aug 17, 2016 | Jul 24, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub