ZeroHour

CVE-2016-7406

CVSS 3.0
9.8 critical
EPSS
10%p95
Published
()
Modified
Description

Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.

Vendors
dropbear ssh project
Products
dropbear ssh
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.