CVE-2017-2659
NONE EPSS 71.2%
Published Mar 21, 20197y ago · Modified Jun 17, 20262w ago
Published Mar 21, 2019 7y ago
Last Modified Jun 17, 2026 2w ago
Description
It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.
Threat Intelligence
EPSS Exploit Probability
71.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 2
CWE-209
CWE-287 Improper Authentication Authentication
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| dropbear_ssh_project | dropbear_ssh | * | <2013.59 |
References 2
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2659
- secure.ucc.asn.au https://secure.ucc.asn.au/hg/dropbear/rev/d7784616409a#l1.86
Remediation
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2659
- secure.ucc.asn.au https://secure.ucc.asn.au/hg/dropbear/rev/d7784616409a#l1.86