CVE-2016-20012: Netapp Clustered Data Ontap
Medium severity, CVSS 5.3. EPSS: 5.3% chance of exploitation in the next 30 days.
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product
Affected products
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Netapp Solidfire: affected versions not specified
- OpenBSD OpenSSH: up to and including 8.7
Published 2021-09-15. Last modified 2026-06-17.