Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-60001

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

A flaw was found in OpenSSH's SSH daemon (sshd). A remote attacker could exploit this vulnerability by repeatedly attempting authentication. The flaw allows the attacker to bypass the intended minimum authentication delay, which can facilitate brute-force attacks. This makes it easier for an attacker to guess valid credentials, potentially leading to unauthorized access or a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshFix deferred
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat Enterprise Linux 8opensshFix deferred
Red Hat Enterprise Linux 9opensshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesopenssh-main-10.4p1-1.hum1FixedRHSA-2026:3738209.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-307
https://bugzilla.redhat.com/show_bug.cgi?id=2497938openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay

EPSS

Процентиль: 21%
0.00291
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
25 дней назад

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

CVSS3: 6.5
nvd
25 дней назад

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

CVSS3: 6.5
msrc
24 дня назад

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

CVSS3: 6.5
debian
25 дней назад

sshd in OpenSSH before 10.4 does not always honor the minimum authenti ...

CVSS3: 6.5
github
25 дней назад

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

EPSS

Процентиль: 21%
0.00291
Низкий

6.5 Medium

CVSS3