Vulnerability Name: | CVE-2007-2768 (CCN-34490) | ||||||||
Assigned: | 2007-04-24 | ||||||||
Published: | 2007-04-24 | ||||||||
Updated: | 2021-04-01 | ||||||||
Summary: | OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:H/RL:U/RC:UR)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Apr 24 2007 - 04:10:27 CDT Re: [Full-disclosure] OpenSSH - System Account Enumeration if S/Key is used Source: FULLDISC Type: Broken Link 20070424 Re: OpenSSH - System Account Enumeration if S/Key is used Source: MITRE Type: CNA CVE-2007-2768 Source: CCN Type: OpenSSH Web page OpenSSH Source: CCN Type: One Time Passwords in Everything Web site OPIE Source: OSVDB Type: Broken Link 34601 Source: CCN Type: OSVDB ID: 34601 OPIE w/ OpenSSH Account Enumeration Source: CCN Type: OSVDB ID: 36207 OPIE accessfile.c Unspecified Off-by-one Remote DoS Source: CCN Type: BID-23669 Retired: OPIE Accessfile.C Remote Denial of Service Vulnerability Source: XF Type: UNKNOWN openssh-opie-information-disclosure(34490) Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20191107-0002/ | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |