CVE-2019-16905: Netapp Cloud Backup
High severity, CVSS 7.8. EPSS: 2.2% chance of exploitation in the next 30 days.
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.
Affected products
- Netapp Cloud Backup: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- OpenBSD OpenSSH: from 7.7, up to and including 7.9; from 8.0, before 8.1 (fixed in 8.1)
- Siemens Scalance x204rna Ecc Firmware: before 3.2.7 (fixed in 3.2.7)
- Siemens Scalance x204rna Firmware: before 3.2.7 (fixed in 3.2.7)
Published 2019-10-09. Last modified 2026-06-17.