GHSA-fq52-jg4q-73hp · Severity: high — sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer...
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
Conclusion & alert: CVE-2016-10708 is rated Moderate Risk (60.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 3.12%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-30 | 2.92% | 3.12% | +0.20% |
| 2 | 2026-03-25 | 3.12% | 2.92% | -0.20% |
| 3 | 2026-03-19 | — | 3.12% | — |
Full EPSS history (53 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-fq52-jg4q-73hp · Severity: high — sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2016-10708 not yet assigned priority: Debian including 1 source packages (openssh), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2016-10708 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2016-10708 |
suse
|
medium | CVE-2016-10708 severity moderate: SUSE including 30 source package names (openssh-6.2p2-0.41.5.1, openssh-6.6p1-36.3.1, …), 92 product×package rows across 26 product lines (SUSE Enterprise Storage 4, SUSE Linux Enterprise Desktop 12 SP3, … (26 product lines)): Fixed 92. | https://www.suse.com/security/cve/CVE-2016-10708/ |
ubuntu
|
low | CVE-2016-10708 low priority: Ubuntu including 1 source packages (openssh), 11 status rows across 11 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, trusty, upstream, xenial): not-affected 8, released 3. | https://ubuntu.com/security/CVE-2016-10708 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openbsd | openssh | < 7.4 | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* |
| debian | debian_linux | 7.0 | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 14.04 | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 18.04 | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:*:*:*:* |
| netapp | cloud_backup | — | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* |
| netapp | data_ontap | — | cpe:2.3:a:netapp:data_ontap:-:*:*:*:*:7-mode:*:* |
| netapp | data_ontap_edge | — | cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:* |
| netapp | oncommand_unified_manager | >= 9.4 | cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:vsphere:*:* |
| netapp | service_processor | — | cpe:2.3:a:netapp:service_processor:-:*:*:*:*:*:*:* |
| netapp | storagegrid | — | cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:* |
| netapp | storagegrid_webscale | — | cpe:2.3:a:netapp:storagegrid_webscale:-:*:*:*:*:*:*:* |
| netapp | clustered_data_ontap | — | cpe:2.3:o:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* |
| netapp | vasa_provider | — | cpe:2.3:a:netapp:vasa_provider:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://blog.swiecki.net/2018/01/fuzzing-tcp-servers.html | Patch Third Party Advisory |
| http://www.securityfocus.com/bid/102780 | Third Party Advisory VDB Entry |
| https://anongit.mindrot.org/openssh.git/commit/?id=28652bca29046f62c7045e933e6b931de1d16737 | Patch Third Party Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-676336.pdf | |
| https://kc.mcafee.com/corporate/index?page=content&id=SB10284 | |
| https://lists.debian.org/debian-lts-announce/2018/01/msg00031.html | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html | Mailing List Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20180423-0003/ | Third Party Advisory |
| https://support.f5.com/csp/article/K32485746?utm_source=f5support&%3Butm_medium=RSS | |
| https://usn.ubuntu.com/3809-1/ | Third Party Advisory |
| https://www.openssh.com/releasenotes.html | Release Notes Vendor Advisory |