Vulnerability Details CVE-2018-15919
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.7%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2018-15919
-
cpe:2.3:a:netapp:cloud_backup:-
-
cpe:2.3:a:netapp:data_ontap_edge:-
-
cpe:2.3:a:netapp:ontap_select_deploy:-
-
cpe:2.3:a:netapp:steelstore:-
-
cpe:2.3:a:openbsd:openssh:5.9
-
cpe:2.3:a:openbsd:openssh:6.0
-
cpe:2.3:a:openbsd:openssh:6.1
-
cpe:2.3:a:openbsd:openssh:6.2
-
cpe:2.3:a:openbsd:openssh:6.3
-
cpe:2.3:a:openbsd:openssh:6.4
-
cpe:2.3:a:openbsd:openssh:6.5
-
cpe:2.3:a:openbsd:openssh:6.6
-
cpe:2.3:a:openbsd:openssh:6.7
-
cpe:2.3:a:openbsd:openssh:6.8
-
cpe:2.3:a:openbsd:openssh:6.9
-
cpe:2.3:a:openbsd:openssh:7.0
-
cpe:2.3:a:openbsd:openssh:7.1
-
cpe:2.3:a:openbsd:openssh:7.2
-
cpe:2.3:a:openbsd:openssh:7.3
-
cpe:2.3:a:openbsd:openssh:7.4
-
cpe:2.3:a:openbsd:openssh:7.5
-
cpe:2.3:a:openbsd:openssh:7.6
-
cpe:2.3:a:openbsd:openssh:7.7
-
cpe:2.3:a:openbsd:openssh:7.8
-
cpe:2.3:h:netapp:cn1610:-
-
cpe:2.3:o:netapp:cn1610_firmware:-