sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 6.1 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 7.1 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 7.2 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Alpine Linux | — | Upgrade openssh | Aug 30, 2017 | Feb 13, 2017 |
| Amazon_linux | — | Upgrade openssh | Oct 3, 2017 | Jul 24, 2016 |
| Centos_linux | — | Upgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-serverUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-cavsUpgrade openssh-debuginfoUpgrade openssh-clientsUpgrade openssh-server-sysvinitUpgrade openssh-keycat | Sep 1, 2017 | Jul 24, 2016 |
| Debian | — | Upgrade openssh | Jul 24, 2016 | Jul 24, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Dec 23, 2016 |
| Freebsd | — | Upgrade openssh-portable | Dec 10, 2025 | Sep 1, 2016 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Feb 13, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade opensshUpgrade openssh-keycatUpgrade openssh-clientsUpgrade openssh-serverUpgrade openssh-askpass | Nov 30, 2017 | Feb 13, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssh-serverUpgrade openssh-askpassUpgrade opensshUpgrade openssh-clientsUpgrade openssh-keycat | Nov 30, 2017 | Feb 13, 2017 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory9 | Nov 30, 2017 | Feb 13, 2017 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 7.3 | Mar 13, 2017 | Feb 13, 2017 |
| Oracle Solaris | — | Upgrade system/library to version 0.5.11-0.175.3.28.0.4.0 on Solaris 11.3Upgrade network/openssh to version 7.3.0.1-0.175.3.15.0.2.0 on Solaris 11.3 | May 29, 2017 | Feb 13, 2017 |
| Oracle_linux | — | Upgrade openssh-cavsUpgrade openssh-askpassUpgrade openssh-clientsUpgrade opensshUpgrade openssh-serverUpgrade openssh-server-sysvinitUpgrade pam_ssh_agent_authUpgrade openssh-ldapUpgrade openssh-keycat | Aug 8, 2017 | Jul 14, 2016 |
| Panos | — | Upgrade PAN-OS 7.0 to the latest versionUpdate PAN-OS 6.1 to the latest workaround for your deviceUpdate PAN-OS 7.1 to the latest workaround for your deviceUpdate PAN-OS 6.0 to the latest workaround for your device | Nov 18, 2016 | Jul 24, 2016 |
| Redhat_linux | — | Upgrade openssh-ldapUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-cavsUpgrade openssh-serverUpgrade openssh-askpassUpgrade openssh-debuginfoNo solution existsUpgrade openssh-keycatUpgrade openssh-server-sysvinitUpgrade openssh-clients | Aug 3, 2017 | Jul 24, 2016 |
| Suse | — | Upgrade openssh-serverUpgrade openssh-openssl1Upgrade openssh-helpersUpgrade openssh-askpass-gnomeUpgrade openssh-askpassUpgrade openssh-fipsUpgrade openssh-commonUpgrade opensshUpgrade openssh-openssl1-helpersUpgrade openssh-clients | Sep 12, 2016 | Jul 24, 2016 |
| Ubuntu | — | Upgrade openssh-server | Aug 17, 2016 | Jul 24, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub