Unrated severityNVD Advisory· Published May 12, 2003· Updated Apr 16, 2026
CVE-2003-0190
CVE-2003-0190
Description
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
Affected products
6- cpe:2.3:o:siemens:scalance_x204rna_ecc_firmware:*:*:*:*:*:*:*:*Range: <3.2.7
- cpe:2.3:o:siemens:scalance_x204rna_firmware:*:*:*:*:*:*:*:*Range: <3.2.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.securityfocus.com/bid/7467nvdBroken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- marc.infonvdThird Party Advisory
- marc.infonvdThird Party Advisory
- cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfnvdThird Party Advisory
- lab.mediaservice.net/advisory/2003-01-openssh.txtnvdBroken Link
- lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2003-222.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2003-224.htmlnvdBroken Link
- www.turbolinux.com/security/TLSA-2003-31.txtnvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A445nvdBroken Link
News mentions
0No linked articles in our index yet.