CVE Feed

    Dashboard / CVE / CVE-2019-16905

    CVE-2019-16905

    OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

    Published:Aug 28, 2019
    Last Modified:Apr 23, 2025
    EPS:Oct 9, 2019
    EPSS Score:0.00269
    CVSS Score:7.8

    Affected Products

    Vendor
    Netapp
    Product
    Cloud Backup
    Vendor
    Netapp
    Product
    Steelstore Cloud Integrated Storage
    Vendor
    Openbsd
    Product
    Openssh
    Vendor
    Siemens
    Product
    Scalance X204rna
    Vendor
    Siemens
    Product
    Scalance X204rna Ecc
    Vendor
    Siemens
    Product
    Scalance X204rna Ecc Firmware
    Vendor
    Siemens
    Product
    Scalance X204rna Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High