CVE-2013-4434
EPSS 5.7%
Description
Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.
How to fix CVE-2013-4434
To remediate CVE-2013-4434, upgrade the affected package to a fixed version below.
- Debian/dropbear—upgrade to 2012.55-1.4 or later
Is CVE-2013-4434 being exploited?
Moderate — EPSS is 5.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2012.55-1.4