CVE-2015-5600
8.1 HIGHThe kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-int...
Published: 2015-08-03 · Last updated: 2026-05-27
Severity and scoring
- CVSS
- 8.1 HIGH
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-264, CWE-400
Affected products
| Vendor | Product |
|---|---|
| openbsd | openssh |
Description
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2015-5600
- [Other]http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c
- [Other]http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c.diff?r1=1.42&r2=1.43&f=h
- [Other]http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10697
- [Other]http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165170.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162955.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.html
- [Other]http://openwall.com/lists/oss-security/2015/07/23/4
- [Other]http://rhn.redhat.com/errata/RHSA-2016-0466.html
- [Exploit reference]http://seclists.org/fulldisclosure/2015/Jul/92
- [Other]http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- [Other]http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- [Other]http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- [Other]http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- [Other]http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- [Other]http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- [Other]http://www.securityfocus.com/bid/75990
- [Other]http://www.securityfocus.com/bid/91787
- [Other]http://www.securityfocus.com/bid/92012
- [Other]http://www.securitytracker.com/id/1032988
- [Other]http://www.ubuntu.com/usn/USN-2710-1
- [Other]http://www.ubuntu.com/usn/USN-2710-2
- [Other]https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- [Other]https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05128992
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667
- [Other]https://kc.mcafee.com/corporate/index?page=content&id=SB10136
- [Other]https://kc.mcafee.com/corporate/index?page=content&id=SB10157
- [Other]https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html
- [Other]https://security.gentoo.org/glsa/201512-04
- [Other]https://security.netapp.com/advisory/ntap-20151106-0001/
- [Other]https://support.apple.com/kb/HT205031
- [Other]https://www.arista.com/en/support/advisories-notices/security-advisories/1174-security-advisory-12
- [Other]http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c
- [Other]http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c.diff?r1=1.42&r2=1.43&f=h
- [Other]http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10697
- [Other]http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165170.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162955.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.html
- [Other]http://openwall.com/lists/oss-security/2015/07/23/4
- [Other]http://rhn.redhat.com/errata/RHSA-2016-0466.html
- [Exploit reference]http://seclists.org/fulldisclosure/2015/Jul/92
- [Other]http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- [Other]http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- [Other]http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- [Other]http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- [Other]http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- [Other]http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- [Other]http://www.securityfocus.com/bid/75990
- [Other]http://www.securityfocus.com/bid/91787
- [Other]http://www.securityfocus.com/bid/92012
- [Other]http://www.securitytracker.com/id/1032988
- [Other]http://www.ubuntu.com/usn/USN-2710-1
- [Other]http://www.ubuntu.com/usn/USN-2710-2
- [Other]https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- [Other]https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05128992
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667
- [Other]https://kc.mcafee.com/corporate/index?page=content&id=SB10136
- [Other]https://kc.mcafee.com/corporate/index?page=content&id=SB10157
- [Other]https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html
- [Other]https://security.gentoo.org/glsa/201512-04
- [Other]https://security.netapp.com/advisory/ntap-20151106-0001/
- [Other]https://support.apple.com/kb/HT205031
- [Other]https://www.arista.com/en/support/advisories-notices/security-advisories/1174-security-advisory-12
Related CVEs
Same vendor
- CVE-2026-3497 — Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions (7.5 HIGH)
- CVE-2023-51767 — OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer ... (7.0 HIGH)
- CVE-2023-51384 — In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied (5.5 MEDIUM)
- CVE-2023-28531 — ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints (9.8 CRITICAL)
- CVE-2023-25136 — OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling (6.5 MEDIUM)
Same CWE
- CVE-2026-12325 — Denial-of-service in the Graphics: ImageLib component (6.5 MEDIUM)
- CVE-2026-12319 — Denial-of-service in the Audio/Video: Playback component (6.5 MEDIUM)
- CVE-2026-50889 — An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending ... (7.5 HIGH)
- CVE-2026-50882 — An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted PO... (7.5 HIGH)
- CVE-2026-50879 — An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a ... (7.5 HIGH)