Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-0777

58
FAUCET Score

CVE-2016-0777 is an information disclosure vulnerability in OpenSSH client versions 5.x, 6.x, and 7.x before 7.1p2, affecting products from vendors like Apple, HP, and Oracle. A malicious OpenSSH server can exploit a flaw in the resend_bytes function to extract sensitive data, such as private keys, from the client's memory. This medium-severity vulnerability (CVSS 6.5) has a high confidentiality impact, is network-exploitable with low attack complexity, and does not require user interaction. While not listed on the KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered significant community discussion and media attention, indicating a recognized risk.

Impacted Technologies

VendorProductVersion(s)CPE
9.318CPE matchmatch criteria
cpe:2.3:a:sophos:unified_threat_management_software:9.318:*:*:*:*:*:*:*
9.353CPE matchmatch criteria
cpe:2.3:a:sophos:unified_threat_management_software:9.353:*:*:*:*:*:*:*
7CPE matchmatch criteria
cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
11.3CPE matchmatch criteria
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
5.0CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:5.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.5MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
63.47%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.6347 is in the 100th percentile among its peer group of 21,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

latchsetpatch availablevia llm_extracted
Fixed in: 7.1p2
View patch
nodejspatch availablevia llm_extracted
Fixed in: 7.1p2
View patch
openldappatch availablevia llm_extracted
Fixed in: 7.1p2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssh-0:6.6.1p1-23.el7_2
View patch
traefikpatch availablevia llm_extracted
Fixed in: 7.1p2
View patch

Vendor Advisories (5)

redhatCVE-2016-0777Moderate

OpenSSH: Client Information leak due to use of roaming connection feature

Jan 14, 2016
openldapllm-openldap-b3332402b2969b0d

Information disclosure vulnerability in OpenSSH clients.

Jan 14, 2016
traefikllm-traefik-d6a6f9be33357f1bHIGH

Information disclosure in OpenSSH clients via malicious server

Jan 14, 2016
nodejsllm-nodejs-236af00f01df7b46

OpenSSH clients vulnerable to information disclosure that may allow a malicious server to retrieve private keys.

Jan 14, 2016
latchsetllm-latchset-8ec4832f5a1a3c4c

Information disclosure vulnerability in OpenSSH clients.

Jan 14, 2016

References

kb.juniper.net / InfoCenter/index
Third Party Advisory
lists.apple.com / archives/security-announce/2016/Mar/msg00004.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2016-February/176516.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2016-January/175592.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2016-January/175676.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2016-January/176349.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00006.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00007.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00008.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00009.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00013.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00014.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html
Third Party AdvisoryVDB Entry
blogs.sophos.com / 2016/02/17/utm-up2date-9-354-released
Third Party Advisory
blogs.sophos.com / 2016/02/29/utm-up2date-9-319-released
Third Party Advisory
bto.bluecoat.com / security-advisory/sa109
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-412672.pdf
seclists.org / fulldisclosure/2016/Jan/44
Mailing ListThird Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
security.freebsd.org / advisories/FreeBSD-SA-16:07.openssh.asc
Third Party Advisory
security.gentoo.org / glsa/201601-01
Third Party Advisory
support.apple.com / HT206167
Third Party Advisory
debian.org / security/2016/dsa-3446
Third Party Advisory
openssh.com / txt/release-7.1p2
Vendor Advisory
openwall.com / lists/oss-security/2016/01/14/7
Mailing ListThird Party Advisory
oracle.com / technetwork/topics/security/bulletinoct2015-2511968.html
Third Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinjan2016-2867209.html
Third Party Advisory
securityfocus.com / archive/1/537295/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/80695
Third Party AdvisoryVDB Entry
securitytracker.com / id/1034671
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2869-1
Third Party Advisory