5.3
CVSSv3

CVE-2016-20012

Published: 15/09/2021 Updated: 11/04/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

OpenSSH up to and including 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh

netapp ontap select deploy administration utility -

netapp clustered data ontap -

netapp solidfire -

netapp hci management node -

Vendor Advisories

OpenSSH through 87 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct This occurs because a challenge is sent only when that combination could be valid for a login session ...
PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION ...

Github Repositories

Nmap's XML result parse and NVD's CPE correlation to search CVE.

CrowFlag This script analyses the Nmap XML scanning results, parses each CPE context and correlates to search CVE on NIST You can use that to find public vulnerabilities in services View Code · Report Bug · View Wiki Getting Started: Before we start Tested using python 3615 (for manual installation) If any error rai

Terraform to Create Rocky Linux on KVM/Libvirt

terraform-rockylinux-libvirt Terraform to Create Rocky Linux on KVM/Libvirt Requirements Name Version terraform = 157 libvirt 071 Providers Name Version libvirt 071 template n/a Inputs Name Description Type Required rocky9_cloudinit_disk Qcow2 cloud-init location any yes rocky9_cloudinit_pool Which Pool to located cloud-initiso any