Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-5794

21
FAUCET Score

CVE-2006-5794 describes an unspecified vulnerability in the sshd Privilege Separation Monitor of OpenSSH before version 4.5, affecting OpenBSD and OpenSSH. This flaw could lead to weaker authentication verification, potentially allowing attackers to bypass authentication. With a CVSS score of 7.5 (High), it presents a network-based attack vector with low complexity, potentially impacting confidentiality, integrity, and availability. While initially believed to require leveraging unknown vulnerabilities in unprivileged processes, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.4CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.68%
Probability of exploitation in next 30 days
EPSS Percentile
84.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0268 is in the 72nd percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: openssh-0:3.6.1p2-33.30.13
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openssh-0:3.9p1-8.RHEL4.17.1
View patch

Vendor Advisories (1)

redhatCVE-2006-5794Low

OpenSSH privilege separation flaw

Nov 7, 2006

References

patches.sgi.com / support/free/security/advisories/20061201-01-P.asc
rhn.redhat.com / errata/RHSA-2006-0738.html
secunia.com / advisories/22771
PatchVendor Advisory
secunia.com / advisories/22772
secunia.com / advisories/22773
PatchVendor Advisory
secunia.com / advisories/22778
secunia.com / advisories/22814
secunia.com / advisories/22872
secunia.com / advisories/22932
secunia.com / advisories/23513
secunia.com / advisories/23680
secunia.com / advisories/24055
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/30120
issues.rpath.com / browse/RPL-766
sourceforge.net / project/shownotes.php
sourceforge.net / project/shownotes.php
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11840
support.avaya.com / elmodocs2/security/ASA-2007-048.htm
mandriva.com / security/advisories
novell.com / linux/security/advisories/2006_26_sr.html
openpkg.org / security/advisories/OpenPKG-SA-2006.032-openssh.html
openssh.org / txt/release-4.5
securityfocus.com / archive/1/451100/100/0/threaded
securityfocus.com / bid/20956
Patch
vmware.com / support/vi3/doc/esx-3069097-patch.html
vmware.com / support/vi3/doc/esx-9986131-patch.html
vupen.com / english/advisories/2006/4399
vupen.com / english/advisories/2006/4400