CVE-2019-12953: Medium severity dropbear ssh vulnerability
Published Dec 30, 2020
·Updated
Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.
Affected Software
1 affected component
Dropbear Ssh Project Dropbear Ssh>=2011.54<=2018.76
Event History
Dec 30, 2020
CVE Published
via MITRE·07:33 PM
Data Sourced
via MITRE·07:33 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Dropbear?
The vulnerability ID for this issue in Dropbear is CVE-2019-12953.
2
What is the severity level of CVE-2019-12953?
The severity level of CVE-2019-12953 is medium with a CVSS score of 5.3.
3
What is the affected software version range for CVE-2019-12953?
CVE-2019-12953 affects Dropbear versions 2011.54 through 2018.76.
4
How can the inconsistent failure delay issue in Dropbear be exploited?
The inconsistent failure delay in Dropbear may lead to revealing valid usernames.
5
Is CVE-2019-12953 the same as CVE-2018-15599 in Dropbear?
No, CVE-2019-12953 in Dropbear is a different issue than CVE-2018-15599.