CVE Vulnerabilities

CVE-2007-2243

Improper Authentication

Published: Apr 25, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
OpensshOpenbsd1.2 (including)1.2 (including)
OpensshOpenbsd1.2.1 (including)1.2.1 (including)
OpensshOpenbsd1.2.2 (including)1.2.2 (including)
OpensshOpenbsd1.2.3 (including)1.2.3 (including)
OpensshOpenbsd1.2.27 (including)1.2.27 (including)
OpensshOpenbsd2.1 (including)2.1 (including)
OpensshOpenbsd2.1.1 (including)2.1.1 (including)
OpensshOpenbsd2.2 (including)2.2 (including)
OpensshOpenbsd2.3 (including)2.3 (including)
OpensshOpenbsd2.5 (including)2.5 (including)
OpensshOpenbsd2.5.1 (including)2.5.1 (including)
OpensshOpenbsd2.5.2 (including)2.5.2 (including)
OpensshOpenbsd2.9 (including)2.9 (including)
OpensshOpenbsd2.9.9 (including)2.9.9 (including)
OpensshOpenbsd2.9.9p2 (including)2.9.9p2 (including)
OpensshOpenbsd2.9p1 (including)2.9p1 (including)
OpensshOpenbsd2.9p2 (including)2.9p2 (including)
OpensshOpenbsd3.0 (including)3.0 (including)
OpensshOpenbsd3.0.1 (including)3.0.1 (including)
OpensshOpenbsd3.0.1p1 (including)3.0.1p1 (including)
OpensshOpenbsd3.0.2 (including)3.0.2 (including)
OpensshOpenbsd3.0.2p1 (including)3.0.2p1 (including)
OpensshOpenbsd3.0p1 (including)3.0p1 (including)
OpensshOpenbsd3.1 (including)3.1 (including)
OpensshOpenbsd3.1p1 (including)3.1p1 (including)
OpensshOpenbsd3.2 (including)3.2 (including)
OpensshOpenbsd3.2.2 (including)3.2.2 (including)
OpensshOpenbsd3.2.2p1 (including)3.2.2p1 (including)
OpensshOpenbsd3.2.3p1 (including)3.2.3p1 (including)
OpensshOpenbsd3.3 (including)3.3 (including)
OpensshOpenbsd3.3p1 (including)3.3p1 (including)
OpensshOpenbsd3.4 (including)3.4 (including)
OpensshOpenbsd3.4p1 (including)3.4p1 (including)
OpensshOpenbsd3.5 (including)3.5 (including)
OpensshOpenbsd3.5p1 (including)3.5p1 (including)
OpensshOpenbsd3.6 (including)3.6 (including)
OpensshOpenbsd3.6.1 (including)3.6.1 (including)
OpensshOpenbsd3.6.1p1 (including)3.6.1p1 (including)
OpensshOpenbsd3.6.1p2 (including)3.6.1p2 (including)
OpensshOpenbsd3.7 (including)3.7 (including)
OpensshOpenbsd3.7.1 (including)3.7.1 (including)
OpensshOpenbsd3.7.1p1 (including)3.7.1p1 (including)
OpensshOpenbsd3.7.1p2 (including)3.7.1p2 (including)
OpensshOpenbsd3.8 (including)3.8 (including)
OpensshOpenbsd3.8.1 (including)3.8.1 (including)
OpensshOpenbsd3.8.1p1 (including)3.8.1p1 (including)
OpensshOpenbsd3.9 (including)3.9 (including)
OpensshOpenbsd3.9.1 (including)3.9.1 (including)
OpensshOpenbsd3.9.1p1 (including)3.9.1p1 (including)
OpensshOpenbsd4.0 (including)4.0 (including)
OpensshOpenbsd4.0p1 (including)4.0p1 (including)
OpensshOpenbsd4.1 (including)4.1 (including)
OpensshOpenbsd4.1p1 (including)4.1p1 (including)
OpensshOpenbsd4.2 (including)4.2 (including)
OpensshOpenbsd4.2p1 (including)4.2p1 (including)
OpensshOpenbsd4.3 (including)4.3 (including)
OpensshOpenbsd4.3p1 (including)4.3p1 (including)
OpensshOpenbsd4.3p2 (including)4.3p2 (including)
OpensshOpenbsd4.4 (including)4.4 (including)
OpensshOpenbsd4.4p1 (including)4.4p1 (including)
OpensshOpenbsd4.5 (including)4.5 (including)
OpensshOpenbsd4.6 (including)4.6 (including)
OpensshUbuntudapper*
OpensshUbuntudevel*
OpensshUbuntuedgy*
OpensshUbuntufeisty*
OpensshUbuntugutsy*

Potential Mitigations

References