5

CVE-2007-2243

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.

Data is provided by the National Vulnerability Database (NVD)
OpenbsdOpenssh Version1.2
OpenbsdOpenssh Version1.2.1
OpenbsdOpenssh Version1.2.2
OpenbsdOpenssh Version1.2.3
OpenbsdOpenssh Version1.2.27
OpenbsdOpenssh Version2.1
OpenbsdOpenssh Version2.1.1
OpenbsdOpenssh Version2.2
OpenbsdOpenssh Version2.3
OpenbsdOpenssh Version2.5
OpenbsdOpenssh Version2.5.1
OpenbsdOpenssh Version2.5.2
OpenbsdOpenssh Version2.9
OpenbsdOpenssh Version2.9.9
OpenbsdOpenssh Version2.9.9p2
OpenbsdOpenssh Version2.9p1
OpenbsdOpenssh Version2.9p2
OpenbsdOpenssh Version3.0
OpenbsdOpenssh Version3.0.1
OpenbsdOpenssh Version3.0.1p1
OpenbsdOpenssh Version3.0.2
OpenbsdOpenssh Version3.0.2p1
OpenbsdOpenssh Version3.0p1
OpenbsdOpenssh Version3.1
OpenbsdOpenssh Version3.1p1
OpenbsdOpenssh Version3.2
OpenbsdOpenssh Version3.2.2
OpenbsdOpenssh Version3.2.2p1
OpenbsdOpenssh Version3.2.3p1
OpenbsdOpenssh Version3.3
OpenbsdOpenssh Version3.3p1
OpenbsdOpenssh Version3.4
OpenbsdOpenssh Version3.4p1
OpenbsdOpenssh Version3.5
OpenbsdOpenssh Version3.5p1
OpenbsdOpenssh Version3.6
OpenbsdOpenssh Version3.6.1
OpenbsdOpenssh Version3.6.1p1
OpenbsdOpenssh Version3.6.1p2
OpenbsdOpenssh Version3.7
OpenbsdOpenssh Version3.7.1
OpenbsdOpenssh Version3.7.1p1
OpenbsdOpenssh Version3.7.1p2
OpenbsdOpenssh Version3.8
OpenbsdOpenssh Version3.8.1
OpenbsdOpenssh Version3.8.1p1
OpenbsdOpenssh Version3.9
OpenbsdOpenssh Version3.9.1
OpenbsdOpenssh Version3.9.1p1
OpenbsdOpenssh Version4.0
OpenbsdOpenssh Version4.0p1
OpenbsdOpenssh Version4.1
OpenbsdOpenssh Version4.1p1
OpenbsdOpenssh Version4.2
OpenbsdOpenssh Version4.2p1
OpenbsdOpenssh Version4.3
OpenbsdOpenssh Version4.3p1
OpenbsdOpenssh Version4.3p2
OpenbsdOpenssh Version4.4
OpenbsdOpenssh Version4.4p1
OpenbsdOpenssh Version4.5
OpenbsdOpenssh Version4.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.39% 0.596
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.