Sales Chat - Click Here

Open SSH with SHA256 or SHA 512 used for password hashing (CVE-2016-6210)


Mar 10, 2023

OpenSSH when SHA256 or SHA512 are used for user password hashing (CVE-2016-6210)

Summary

This vulnerability applies when SHA256 or SHA512 are used for user password hashing. No Buffalo NAS products use SHA256 or SHA512 for user password hashing, and so no Buffalo Sytems are affected by this vulnerability.

Vulnerability ID Vulnerability Overview
CVE-2016-6210 sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.

Affected Supported TeraStations

None

Back to Security Notices

Date Description
3/10/2022 Initial release
X