CVE-2018-15919: Netapp Cloud Backup

Medium severity, CVSS 5.3. EPSS: 3.6% chance of exploitation in the next 30 days.

Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'

Affected products

  • Netapp Cloud Backup: affected versions not specified
  • Netapp CN1610 Firmware: affected versions not specified
  • Netapp Data Ontap Edge: affected versions not specified
  • Netapp Ontap Select Deploy: affected versions not specified
  • Netapp Steelstore: affected versions not specified
  • OpenBSD OpenSSH: from 5.9, up to and including 7.8

Published 2018-08-28. Last modified 2026-06-17.