5
CVSSv2

CVE-1999-1231

Published: 09/06/1999 Updated: 19/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote malicious users to determine user account names on the server.

Vulnerable Product Search on Vulmon Subscribe to Product

ssh ssh2 2.0.10

ssh ssh2 2.0.11

ssh ssh2 2.0.7

ssh ssh2 2.0.8

ssh ssh2 2.0.12

ssh ssh2 2.0.2

ssh ssh2 2.0.9

ssh ssh2 2.0.3

ssh ssh2 2.0.4

ssh ssh2 2.0

ssh ssh2 2.0.1

ssh ssh2 2.0.5

ssh ssh2 2.0.6