openssh: MaxAuthTries limit bypass via duplicates in KbdInteractiveDevices
Published Aug 3, 2015
8.1
HIGHCVSS 3.1
EPSS 9.38%
Description
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
openssh-0:5.3p1-114.el6_7
Fixed · RHSA-2016:0466
Red Hat Enterprise Linux 7
openssh-0:6.6.1p1-22.el7
Fixed · RHSA-2015:2088
Red Hat Enterprise Linux 4
openssh
Will not fix
Red Hat Enterprise Linux 5
openssh
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssh-0:5.3p1-114.el6_7 | Fixed | RHSA-2016:0466 |
| Red Hat Enterprise Linux 7 | openssh-0:6.6.1p1-22.el7 | Fixed | RHSA-2015:2088 |
| Red Hat Enterprise Linux 4 | openssh | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | openssh | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the default OpenSSH sshd configuration in Red Hat Enterprise Linux 4, 5, 6 and 7.
Red Hat mitigation
This issue can be mitigated by disabling keyboard-interactive authentication method. That can be achieved by setting "ChallengeResponseAuthentication no" in the /etc/ssh/sshd_config configuration file and restarting the sshd service.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 27, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (31 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.38% (0.09377) | 95.25th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.30% (0.09302) | 94.72th | v5 (v2026.06.15) |
| Jun 4, 2026 | 78.36% (0.78359) | 99.05th | v4 (v2025.03.14) |
| May 30, 2026 | 74.50% (0.74503) | 98.87th | v4 (v2025.03.14) |
| May 28, 2026 | 77.86% (0.77859) | 99.02th | v4 (v2025.03.14) |
| May 17, 2026 | 73.59% (0.73594) | 98.83th | v4 (v2025.03.14) |
| May 15, 2026 | 69.10% (0.69099) | 98.66th | v4 (v2025.03.14) |
| Apr 9, 2026 | 73.59% (0.73594) | 98.80th | v4 (v2025.03.14) |
| Dec 20, 2025 | 70.91% (0.70907) | 98.64th | v4 (v2025.03.14) |
| Dec 7, 2025 | 55.15% (0.55152) | 97.94th | v4 (v2025.03.14) |
| Dec 1, 2025 | 43.71% (0.43711) | 97.39th | v4 (v2025.03.14) |
| Nov 19, 2025 | 69.53% (0.69532) | 98.69th | v4 (v2025.03.14) |
| Nov 18, 2025 | 64.14% (0.64144) | 98.42th | v4 (v2025.03.14) |
| Nov 9, 2025 | 28.45% (0.28454) | 96.30th | v4 (v2025.03.14) |
| Sep 17, 2025 | 32.84% (0.32841) | 96.75th | v4 (v2025.03.14) |
| Aug 16, 2025 | 30.16% (0.30157) | 96.50th | v4 (v2025.03.14) |
| Jun 8, 2025 | 33.75% (0.33752) | 96.71th | v4 (v2025.03.14) |
| Mar 30, 2025 | 40.12% (0.40121) | 97.05th | v4 (v2025.03.14) |
| Mar 29, 2025 | 44.31% (0.44306) | 96.37th | v4 (v2025.03.14) |
| Mar 21, 2025 | 40.12% (0.40121) | 97.08th | v4 (v2025.03.14) |
| Mar 17, 2025 | 44.22% (0.44225) | 97.25th | v4 (v2025.03.14) |
| Mar 15, 2025 | 31.27% (0.31272) | 97.10th | v3 (v2023.03.01) |
| Jan 27, 2025 | 34.65% (0.34648) | 97.16th | v3 (v2023.03.01) |
| Aug 12, 2024 | 36.27% (0.36266) | 97.22th | v3 (v2023.03.01) |
| Dec 6, 2023 | 16.44% (0.16437) | 95.47th | v3 (v2023.03.01) |
| Jul 15, 2023 | 19.08% (0.19081) | 95.60th | v3 (v2023.03.01) |
| May 8, 2023 | 21.56% (0.21564) | 95.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 19.08% (0.19081) | 95.42th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (38)
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c.diff?r1=1.42&r2=1.43&f=h
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10697
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html vendor-advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165170.html vendor-advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162955.html vendor-advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.html vendor-advisory
- http://openwall.com/lists/oss-security/2015/07/23/4 mailing-list
- http://rhn.redhat.com/errata/RHSA-2016-0466.html vendor-advisory
- http://seclists.org/fulldisclosure/2015/Jul/92 mailing-listExploit
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/bid/75990 vdb-entry
- http://www.securityfocus.com/bid/91787 vdb-entry
- http://www.securityfocus.com/bid/92012 vdb-entry
- http://www.securitytracker.com/id/1032988 vdb-entry
- http://www.ubuntu.com/usn/USN-2710-1 vendor-advisory
- http://www.ubuntu.com/usn/USN-2710-2 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2015-5600 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1245969 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05128992
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667
- https://kc.mcafee.com/corporate/index?page=content&id=SB10136
- https://kc.mcafee.com/corporate/index?page=content&id=SB10157
- https://kingcope.wordpress.com/2015/07/16/openssh-keyboard-interactive-authentication-brute-force-vulnerability-maxauthtries-bypass/
- https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2015-5600
- https://security.gentoo.org/glsa/201512-04 vendor-advisory
- https://security.netapp.com/advisory/ntap-20151106-0001/
- https://support.apple.com/kb/HT205031
- https://www.arista.com/en/support/advisories-notices/security-advisories/1174-security-advisory-12
- https://www.cve.org/CVERecord?id=CVE-2015-5600
Change history (0)
No recorded changes yet.