5

CVE-1999-1231

Exploit

ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

Data is provided by the National Vulnerability Database (NVD)
SshSsh2 Version2.0
SshSsh2 Version2.0.1
SshSsh2 Version2.0.2
SshSsh2 Version2.0.3
SshSsh2 Version2.0.4
SshSsh2 Version2.0.5
SshSsh2 Version2.0.6
SshSsh2 Version2.0.7
SshSsh2 Version2.0.8
SshSsh2 Version2.0.9
SshSsh2 Version2.0.10
SshSsh2 Version2.0.11
SshSsh2 Version2.0.12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.96% 0.744
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N