7.6
CVSSv2

CVE-2003-1562

Published: 31/12/2003 Updated: 13/12/2022
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

sshd in OpenSSH 3.6.1p2 and previous versions, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote malicious users to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh 2

openbsd openssh 3.2.2

openbsd openssh 3.1

openbsd openssh 3.0.2p1

openbsd openssh 1.5.8

openbsd openssh 2.1.1

openbsd openssh 3.2.3p1

openbsd openssh 3.1p1

openbsd openssh 2.5.1

openbsd openssh 2.9.9p2

openbsd openssh 3.6.1p2

openbsd openssh 3.0

openbsd openssh 1.2.1

openbsd openssh 2.2

openbsd openssh 3.2

openbsd openssh 3.6

openbsd openssh 1.5.7

openbsd openssh 1.2.3

openbsd openssh 3.5p1

openbsd openssh 2.3.1

openbsd openssh 3.0.1p1

openbsd openssh 2.1

openbsd openssh 1.2

openbsd openssh 3.3

openbsd openssh 3.2.2p1

openbsd openssh 3.0.2

openbsd openssh 3.4p1

openbsd openssh 3.6.1p1

openbsd openssh 3.0.1

openbsd openssh 2.9.9

openbsd openssh 3.6.1

openbsd openssh 1.2.2

openbsd openssh 2.9p1

openbsd openssh 2.9

openbsd openssh 1.2.27

openbsd openssh 2.5.2

openbsd openssh 2.3

openbsd openssh 3.4

openbsd openssh 3.5

openbsd openssh 2.5

openbsd openssh 3.0p1

openbsd openssh 3.3p1

openbsd openssh 1.3

openbsd openssh 2.9p2

openbsd openssh 1.5