CVE-2016-6515
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote...
- Published
- Aug 7, 2016
- Updated
- Aug 6, 2024
- Assigning CNA
- mitre
- Evidence observed
- Dec 7, 2016
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:CModerate · next 30 days
- Percentile
- 98.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.
Sources
4Docker container providing a vulnerable environment for CVE-2016-6515 exploitation, part of the Cved framework for managing and testing against known vulnerabilities.
- exploit-CVE-2016-6515Exploit
OpenSSH remote DOS exploit and vulnerable container
- openssh_dosPoC
Proof-of-concept exploit for CVE-2016-6515, crashing OpenSSH servers via oversized password payloads that exhaust CPU resources during hash processing.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.