VDB

CVE-2013-4434

CVE-2013-4434 REJECTED

Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.

EPSS 1.91% · 83.7th percentile

Risk Scores

EPSS Score
1.91%
83.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSdropbear0, 2012.55-1.3ubuntu1, 2012.55-1.4ubuntu1

Timeline

  • Oct 25, 2013 CVE Published
  • Jun 20, 2016 PoC Published
  • Jul 20, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 12, 2024 EPSS Score
  • Dec 17, 2024 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 18, 2025 EPSS Score
  • Mar 19, 2025 EPSS Score
  • Mar 20, 2025 EPSS Score
  • Mar 21, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›