← Back

CVE-2003-1562

nvd nist
Published: Dec 31, 2003Modified: Apr 16, 2026

JSON object

Loading...
7.6
Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 4.9 / Impact: 10.0
Source: NVD

Description

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.

Affected (45)

Products: Openbsd: Openssh
1 product
Openssh
Configuration A
45 vulnerable
Vulnerable SoftwareAffected Versions
Openbsd
Version 1.2.1
Version 1.2.27
Version 1.2.2
Version 1.2.3
Version 1.2
Version 1.3
Version 1.5.7
Version 1.5.8
Version 1.5
Version 2.1.1
Version 2.1
Version 2.2
Version 2.3.1
Version 2.3
Version 2.5.1
Version 2.5.2
Version 2.5
Version 2.9.9
Version 2.9.9p2
Version 2.9
Version 2.9p1
Version 2.9p2
Version 2
Version 3.0.1
Version 3.0.1p1
Version 3.0.2
Version 3.0.2p1
Version 3.0
Version 3.0p1
Version 3.1
Version 3.1p1
Version 3.2.2
Version 3.2.2p1
Version 3.2.3p1
Version 3.2
Version 3.3
Version 3.3p1
Version 3.4
Version 3.4p1
Version 3.5
Version 3.5p1
Version 3.6.1
Version 3.6.1p1
Version 3.6.1p2
Version 3.6

References (12)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.