CVE-2007-2791

critical

Description

Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified vectors, probably related to timing attacks and AuthInteractiveFailureRandomTimeout.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/34329

http://www.vupen.com/english/advisories/2007/1851

http://www.securitytracker.com/id?1018065

http://www.securityfocus.com/bid/24021

http://secunia.com/advisories/24036

http://osvdb.org/36204

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01007552

Details

Source: Mitre, NVD

Published: 2007-05-22

Updated: 2026-04-23

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.0667