CVE-2016-6210
MEDIUM 5.9EPSS 88.9%
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
- CVSS v3.1
- 5.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.0
- 5.9 MEDIUM
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 88.94% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- medium · CWE-200
- Published
- 2017-02-13
- Updated
- 2026-05-29
Proof-of-concept exploits (8)
- KiPhuong/cve-2016-62100★ · 2025-07-17
- coolbabayaga/CVE-2016-62101★ · 2025-03-14
- eric-conrad/enumer87★ · 2016-08-14
- goomdan/CVE-2016-6210-exploit1★ · 2024-03-23
- justlce/CVE-2016-6210-Exploit3★ · 2019-08-25
- nicoleman0/CVE-2016-6210-OpenSSHd-7.2p20★ · 2025-04-12
- samh4cks/CVE-2016-6210-OpenSSH-User-Enumeration0★ · 2023-09-01
- sh4rknado/SSH-ULTIMATE0★ · 2020-07-27