CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
- Openbsd Openssh
- ≤ 7.2
- Fix
- Available
- CVSS 3.0
- 5.9 MEDIUM
- EPSS
- 88.6% (100th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2017-02-13
CVE-2016-6210 at NVD
20 known exploits for CVE-2016-6210
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2024-6387
cve-2016-6210
CVE-2016-6210
CVE-2016-6210-Exploit
CVE-2016-6210-OpenSSH-User-Enumeration
CVE-2016-6210-OpenSSHd-7.2p2
ssh-enum
CVE-2016-6210-exploit
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Openbsd Openssh
SSH Username Enumeration
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Openbsd Openssh
OpenSSHD 7.2p2 User Enumeration
OpenSSH 7.2p2 - Username Enumeration
OpenSSH 7.2p2 - Username Enumeration
OpenSSHd 7.2p2 - Username Enumeration (2)
OpenSSHd 7.2p2 - Username Enumeration
OpenSSHd 7.2p2 - Username Enumeration
OpenSSHD 7.2p2 User Enumeration
OpenSSHd 7.2p2 - Username Enumeration (1)
SSH Username Enumeration