Dropbear SSH Server prior to 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote malicious users to discover valid usernames.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
dropbear ssh project dropbear ssh |