QID 38903
Date Published: 2023-07-19
QID 38903: OpenSSH Probable User Enumeration Vulnerability
OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the SSH protocol.
OpenSSH contains the following vulnerabilities:
CVE-2016-20012: OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session.
Affected Versions:
OpenSSH versions prior to 8.8
QID Detection Logic:
This unauthenticated detection works by reviewing the version of the OpenSSH service.
Successful exploitation allows a remote attacker to test and confirm if a certain combination of username and public key is known to an SSH server.
- OpenSSH 8.8 -
www.openssh.com/txt/release-8.8
CVEs related to QID 38903
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenSSH 8.8 or later |
|