CVE-2013-4434 REJECTED

Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.

EPSS 1.91% · 83.2th percentile

Risk Scores

EPSS Score
1.91%
83.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSdropbear0, 2012.55-1.3ubuntu1, 2012.55-1.4ubuntu1

Timeline

References

Open in Interactive Console →