7.6

CVE-2003-1562

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.

Data is provided by the National Vulnerability Database (NVD)
OpenbsdOpenssh Version1.2
OpenbsdOpenssh Version1.2.1
OpenbsdOpenssh Version1.2.2
OpenbsdOpenssh Version1.2.3
OpenbsdOpenssh Version1.2.27
OpenbsdOpenssh Version1.3
OpenbsdOpenssh Version1.5
OpenbsdOpenssh Version1.5.7
OpenbsdOpenssh Version1.5.8
OpenbsdOpenssh Version2
OpenbsdOpenssh Version2.1
OpenbsdOpenssh Version2.1.1
OpenbsdOpenssh Version2.2
OpenbsdOpenssh Version2.3
OpenbsdOpenssh Version2.3.1
OpenbsdOpenssh Version2.5
OpenbsdOpenssh Version2.5.1
OpenbsdOpenssh Version2.5.2
OpenbsdOpenssh Version2.9
OpenbsdOpenssh Version2.9.9
OpenbsdOpenssh Version2.9.9p2
OpenbsdOpenssh Version2.9p1
OpenbsdOpenssh Version2.9p2
OpenbsdOpenssh Version3.0
OpenbsdOpenssh Version3.0.1
OpenbsdOpenssh Version3.0.1p1
OpenbsdOpenssh Version3.0.2
OpenbsdOpenssh Version3.0.2p1
OpenbsdOpenssh Version3.0p1
OpenbsdOpenssh Version3.1
OpenbsdOpenssh Version3.1p1
OpenbsdOpenssh Version3.2
OpenbsdOpenssh Version3.2.2
OpenbsdOpenssh Version3.2.2p1
OpenbsdOpenssh Version3.2.3p1
OpenbsdOpenssh Version3.3
OpenbsdOpenssh Version3.3p1
OpenbsdOpenssh Version3.4
OpenbsdOpenssh Version3.4p1
OpenbsdOpenssh Version3.5
OpenbsdOpenssh Version3.5p1
OpenbsdOpenssh Version3.6
OpenbsdOpenssh Version3.6.1
OpenbsdOpenssh Version3.6.1p1
OpenbsdOpenssh Version3.6.1p2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.27% 0.789
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.