CVE-2015-6565 describes a vulnerability in OpenSSH versions 6.8 and 6.9 where sshd sets world-writable permissions for TTY devices, allowing local users to disrupt terminals or potentially achieve other unspecified impacts through escape sequence injection. This vulnerability carries a CVSS score of 7.2, indicating a high severity with local access, low attack complexity, and complete confidentiality, integrity, and availability impacts. While not listed on the KEV catalog, an ExploitDB entry (EDB-41173) exists for local privilege escalation, and there has been some community discussion and media coverage regarding its exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.8CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:6.8:*:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:6.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.