Back to search
CVE-2016-6210
Published: Feb 13, 2017
Modified: May 29, 2026
PUBLISHED
Description
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2017:2563
vendor-advisory
1036319
vdb-entry
20160714 opensshd - user enumeration
mailing-list
DSA-3626
vendor-advisory
40136
exploit
40113
exploit
GLSA-201612-18
vendor-advisory
RHSA-2017:2029
vendor-advisory
91812
vdb-entry
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now