How to Buy
This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.
The remote SSH service is affected by multiple vulnerabilities.
According to its self-reported banner, the version of Dropbear SSH
running on this port is earlier than 2013.59. As such, it is
potentially affected by multiple vulnerabilities :
- A denial of service vulnerability caused by the way the
'buf_decompress()' function handles compressed files.
- User-enumeration is possible due to a timing error when
authenticating users. (CVE-2013-4434)
See also :
Upgrade to the Dropbear SSH 2013.59 or later.
Risk factor :
Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 4.3
Public Exploit Available : true
Nessus Plugin ID: 70545 ()
Bugtraq ID: 6295862993
CVE ID: CVE-2013-4421CVE-2013-4434
Nessus Professional: Scan unlimited IPs, run compliance checks & moreNessus Cloud: The power of Nessus for teams – from the cloud
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.