CVE-2016-6515 is a denial-of-service vulnerability affecting OpenSSH versions prior to 7.3, including those in Fedora and OpenBSD. It allows remote attackers to consume significant CPU resources by sending excessively long passwords during authentication attempts. Rated 7.5 HIGH, this vulnerability requires no user interaction and can be exploited over the network, leading to system unavailability. While not actively exploited in the wild and lacking Metasploit/Nuclei modules, a proof-of-concept exploit exists on ExploitDB, and its high EPSS score indicates a significant likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.2CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:p2:*:*:*:*:*:* | ||
24CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.