CVE-2016-6515
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.
- Openbsd Openssh
- ≤ 7.2
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 58.6% (99th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2016-08-07
CVE-2016-6515 at NVD
8 known exploits for CVE-2016-6515
Proof-of-concept code and exploit modules indexed by Sploitus