id: CVE-2016-6210 info: name: OpenSSH username enumeration < v7.3 author: iamthefrogy,forgedhallpass severity: medium description: OpenSSH before 7.3 is vulnerable to username enumeration and DoS vulnerabilities. reference: - http://seclists.org/fulldisclosure/2016/Jul/51 - https://security-tracker.debian.org/tracker/CVE-2016-6210 - http://openwall.com/lists/oss-security/2016/08/01/2 - https://nvd.nist.gov/vuln/detail/CVE-2016-6210 classification: cvss-metrics: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 5.9 cve-id: CVE-2016-6210 cwe-id: CWE-200 tags: cve,cve2016,network,openssh network: - host: - "{{Hostname}}" - "{{Host}}:22" matchers: - type: regex regex: - '(?i)SSH-2.0-OpenSSH_(?:[1-6][^\d][^\r\n]+|7\.[0-2][^\d][\n^\r]+)' extractors: - type: regex regex: - '(?i)SSH-2.0-OpenSSH_[^\r\n]+'