CVE-2018-15919: Netapp Cloud Backup
Medium severity, CVSS 5.3. EPSS: 3.6% chance of exploitation in the next 30 days.
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'
Affected products
- Netapp Cloud Backup: affected versions not specified
- Netapp CN1610 Firmware: affected versions not specified
- Netapp Data Ontap Edge: affected versions not specified
- Netapp Ontap Select Deploy: affected versions not specified
- Netapp Steelstore: affected versions not specified
- OpenBSD OpenSSH: from 5.9, up to and including 7.8
Published 2018-08-28. Last modified 2026-06-17.