CVE-2016-7406
—CVSS 3.0
9.8 critical
EPSS
10%p95
Published
()
Modified
Description
Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.
- Vendors
- dropbear ssh project
- Products
- dropbear ssh
- Weakness
- CWE-20
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.