Back

HIGH

openssh: MaxAuthTries limit bypass via duplicates in KbdInteractiveDevices

Published Aug 3, 2015

Description

The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list.

Affected products

Remediation

Red Hat statement

This issue does not affect the default OpenSSH sshd configuration in Red Hat Enterprise Linux 4, 5, 6 and 7.

Red Hat mitigation

This issue can be mitigated by disabling keyboard-interactive authentication method. That can be achieved by setting "ChallengeResponseAuthentication no" in the /etc/ssh/sshd_config configuration file and restarting the sshd service.

Metrics

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 3, 2015
Updated May 27, 2026
Reserved Jul 20, 2015
CISA Vulnrichment
Updated May 27, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 16, 2015