VYPR
Unrated severityNVD Advisory· Published May 12, 2003· Updated Jun 16, 2026

CVE-2003-0190

CVE-2003-0190

Description

OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.