CVE-2016-3115 describes multiple CRLF injection vulnerabilities in OpenSSH versions prior to 7.2p2, specifically affecting the sshd component. These flaws, found in the do_authenticated1 and session_x11_req functions, allow remote authenticated users to bypass shell-command restrictions through crafted X11 forwarding data. The vulnerability carries a CVSS v3 score of 6.4 (Medium), indicating a network-based attack with low complexity, requiring low privileges, and potentially leading to low confidentiality and integrity impacts. While not listed in CISA's KEV catalog and lacking Metasploit/Nuclei modules, an ExploitDB entry (EDB-39569) exists, suggesting proof-of-concept exploit code is available, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.2CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:p1:*:*:*:*:*:* | ||
3.2CPE matchmatch criteria | cpe:2.3:o:oracle:vm_server:3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.