Back
CVE-2016-7406
CRITICAL
Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.
Published: Mar 3, 2017
Modified: Jun 17, 2026
CWE-20
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| dropbear_ssh_project | dropbear_ssh | * |
GitHub Security Advisory GHSA-jvpx-9hv9-4qf6
Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute...
References (11)
- http://www.openwall.com/lists/oss-security/2016/09/15/2 Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/92974 Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1376353 Issue Tracking
- https://secure.ucc.asn.au/hg/dropbear/rev/b66a483f3dcb Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201702-23 Patch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2024/Aug/35
- http://www.openwall.com/lists/oss-security/2016/09/15/2 Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/92974 Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1376353 Issue Tracking
- https://secure.ucc.asn.au/hg/dropbear/rev/b66a483f3dcb Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201702-23 Patch, Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
10.49%
Top 5% most likely to be exploited
Threat Score
42.3 / 100
Data Sources
NVD
EPSS
GitHub