vendor:
OpenSSH
by:
Kashinath T
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: OpenSSH
Affected Version From: OpenSSH before 7.3
Affected Version To: OpenSSH before 7.3
Patch Exists: YES
Related CWE: CVE-2016-6515
CPE: a:openssh:openssh
Metasploit:
https://www.rapid7.com/db/vulnerabilities/aix-7.2-openssh_advisory9_cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/aix-5.3-openssh_advisory9_cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/aix-6.1-openssh_advisory9_cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/aix-7.1-openssh_advisory9_cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2016-6515/, https://www.rapid7.com/db/vulnerabilities/openbsd-openssh-cve-2016-6515/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 16.04 LTS, Centos 7
2016
OpenSSH before 7.3 Crypt CPU Consumption (DoS Vulnerability)
If the remote machine is installed and running OpenSSH version prior to 7.3, it does not limit the password length for authentication. Hence, to exploit this vulnerability' we will send a crafted data which is of 90000 characters in length to the 'password' field while attempting to log in to a remote machine via ssh with username as 'root'.
Mitigation:
Upgrade to OpenSSH version 7.3 or later.