AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-5229

LOW · CVSS 2.6 EPSS 54.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-10-10 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.6. It affects Linux. Its EPSS score suggests a 54.2% probability of exploitation in the next 30 days. It may be remotely exploitable.

CVE
CVE-2006-5229
Severity
LOW
CVSS
2.6
EPSS
54.21%
Linux

Original NVD Description

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses take longer for valid usernames than invalid ones, as demonstrated by sshtime. NOTE: as of 20061014, it appears that this issue is dependent on the use of manually-set passwords that causes delays when processing /etc/shadow due to an increased number of rounds.