CVE-2016-6210
OpenSSH sshd Password Hashing Timing Vulnerability
Description
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
INFO
Published Date :
Feb. 13, 2017, 5:59 p.m.
Last Modified :
May 13, 2026, 12:24 a.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 2.0 | MEDIUM | [email protected] | ||||
| CVSS 3.0 | MEDIUM | [email protected] |
Solution
- Update OpenSSH to a non-vulnerable version.
- Apply relevant vendor software updates.
- Reboot the system if required by updates.
Public PoC/Exploit Available at Github
CVE-2016-6210 has a 56 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2016-6210.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2016-6210 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2016-6210
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Autonomous Red Team AI - Nmap + CVE + LLM Pipeline | ~60% recon time reduction | Tested on DVWA, Metasploitable2, HackTheBox
Python HTML Batchfile Shell
None
Python
Python-based suite for network reconnaissance, service enumeration, and CVE correlation. Includes targeted host scanning with packet capture and local subnet discovery.
Python
List of NMAP scripting engine (.nse) script for deep nmap scanning process.
Lua Shell
None
Dockerfile Python Shell
A high-performance, multi-threaded port scanner written in Python, featuring banner grabbing, service detection, and stealth timing for security auditing.
cybersecurity network-security offensive-security penetration-testing port-scanner python red-team
Python
CVE-2016-6210/Openssh 7.2p2 side channel info disclosure POC
Python
This project explores whether modern OpenSSH reveals valid usernames through subtle response or timing differences. Using a controlled lab on Ubuntu 22.04.5 LTS, it also examines the traces such attempts leave behind and how they can be detected.
hydra kali-linux metasploit ssh ubuntu
Jupyter Notebook Python
This document provides a structured security assessment across network packet analysis, FTP traffic decoding, service enumeration, OS fingerprinting, and vulnerability scanning.
None
Lab Week 7 - Vulnerability Analysis (IKB21403)
Una herramienta de terminal (CLI) que actúa como un asistente experto en pentesting. Le pegas el output de cualquier herramienta de seguridad y Claude lo analiza como si fuera un senior pentester a tu lado.
Python
A Python-based network reconnaissance and vulnerability assessment tool using Scapy and Socket.
Python
None
A suite of custom Python security tools built to audit and defend a simulated 16-bit arcade infrastructure.
Python
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2016-6210 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2016-6210 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Status Change by [email protected]
May. 13, 2026
Action Type Old Value New Value -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 21, 2024
Action Type Old Value New Value Added Reference http://seclists.org/fulldisclosure/2016/Jul/51 Added Reference http://www.debian.org/security/2016/dsa-3626 Added Reference http://www.securityfocus.com/bid/91812 Added Reference http://www.securitytracker.com/id/1036319 Added Reference https://access.redhat.com/errata/RHSA-2017:2029 Added Reference https://access.redhat.com/errata/RHSA-2017:2563 Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf Added Reference https://security.gentoo.org/glsa/201612-18 Added Reference https://security.netapp.com/advisory/ntap-20190206-0001/ Added Reference https://www.exploit-db.com/exploits/40113/ Added Reference https://www.exploit-db.com/exploits/40136/ Added Reference https://www.openssh.com/txt/release-7.3 -
CVE Modified by [email protected]
May. 14, 2024
Action Type Old Value New Value -
CVE Modified by [email protected]
Dec. 13, 2022
Action Type Old Value New Value Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf [No Types Assigned] -
CVE Modified by [email protected]
Feb. 07, 2019
Action Type Old Value New Value Added Reference https://security.netapp.com/advisory/ntap-20190206-0001/ [No Types Assigned] -
CVE Modified by [email protected]
Jan. 05, 2018
Action Type Old Value New Value Added Reference https://access.redhat.com/errata/RHSA-2017:2563 [No Types Assigned] Added Reference https://access.redhat.com/errata/RHSA-2017:2029 [No Types Assigned] -
CVE Modified by [email protected]
Nov. 04, 2017
Action Type Old Value New Value Added Reference http://www.debian.org/security/2016/dsa-3626 [No Types Assigned] -
CVE Modified by [email protected]
Sep. 03, 2017
Action Type Old Value New Value Added Reference https://www.exploit-db.com/exploits/40136/ [No Types Assigned] Added Reference https://www.exploit-db.com/exploits/40113/ [No Types Assigned] -
CVE Modified by [email protected]
Sep. 01, 2017
Action Type Old Value New Value Added Reference http://www.securitytracker.com/id/1036319 [No Types Assigned] -
CVE Modified by [email protected]
Jul. 01, 2017
Action Type Old Value New Value Added Reference https://security.gentoo.org/glsa/201612-18 [No Types Assigned] -
Initial Analysis by [email protected]
Mar. 09, 2017
Action Type Old Value New Value Added CVSS V2 (AV:N/AC:M/Au:N/C:P/I:N/A:N) Added CVSS V3 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Changed Reference Type http://seclists.org/fulldisclosure/2016/Jul/51 No Types Assigned http://seclists.org/fulldisclosure/2016/Jul/51 Mailing List, Third Party Advisory Changed Reference Type http://www.securityfocus.com/bid/91812 No Types Assigned http://www.securityfocus.com/bid/91812 Third Party Advisory, VDB Entry Changed Reference Type https://www.openssh.com/txt/release-7.3 No Types Assigned https://www.openssh.com/txt/release-7.3 Release Notes, Vendor Advisory Added CWE CWE-200 Added CPE Configuration OR *cpe:2.3:a:openbsd:openssh:7.2:p2:*:*:*:*:*:* (and previous) -
CVE Modified by [email protected]
Feb. 15, 2017
Action Type Old Value New Value Added Reference http://www.securityfocus.com/bid/91812 [No Types Assigned]