CVE-2013-4434
EPSS 1.9%
Description
Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.
How to fix CVE-2013-4434
To remediate CVE-2013-4434, upgrade the affected package to a fixed version below.
- Debian/dropbear—upgrade to 2012.55-1.4 or later
Is CVE-2013-4434 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2012.55-1.4