CVE-2013-4434
EPSS 1.9%Published: 10/25/2013Modified: 4/28/2026
Also known as:DEBIAN-CVE-2013-4434
Description
Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.
Affected packages (1)
- Debian/dropbearfrom 0, < 2012.55-1.4