CyberRota Analysis
AI-GeneratedOpenSSH versions prior to 10.4 have a vulnerability in the sshd component that fails to consistently enforce the minimum authentication delay, potentially allowing attackers to execute rapid brute-force login attempts. This could lead to unauthorized access to systems relying on affected versions of OpenSSH. Organizations using these versions should prioritize patching to mitigate the risk of credential compromise.
CVE
CVE-2026-60001
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
Original NVD Description
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
Related CVEs
Other vulnerabilities affecting the same vendor(s)