CVE-2013-4434SSH Project Dropbear SSH vulnerability

CWE-1895 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
1.9%
top 16.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateMay 14

Description

Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/dropbear< dropbear 2012.55-1.4 (bookworm)
Debiandropbear_ssh_project/dropbear_ssh< 2012.55-1.4+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7j5m-wjm2-xppv: Dropbear SSH Server before 20132022-05-14
OSV
CVE-2013-4434: Dropbear SSH Server before 20132013-10-25

📋Vendor Advisories

1
Debian
CVE-2013-4434: dropbear - Dropbear SSH Server before 2013.59 generates error messages for a failed logon a...2013

💬Community

1
Bugzilla
CVE-2013-4434 dropbear: user disclosure via authentication failure delays2013-10-10