CVE-2018-15919 describes a username enumeration vulnerability in OpenSSH through version 7.8, specifically within the auth-gss2.c component, affecting products like NetApp and OpenBSD when GSS2 is enabled. This medium-severity vulnerability (CVSS 5.3) allows remote attackers to detect the existence of users on a target system without authentication, with low attack complexity and no user interaction required. While OpenSSH developers do not consider this a vulnerability, it exposes sensitive information. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not on the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.9, <= 7.8CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:steelstore:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.