← All CVEs

CVE-2016-3116

medium · 6.4

CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data.

6.4
CVSS
19.3%
EPSS (exploit prob.)
97th
EPSS percentile
2016-03-22
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Affected products

VendorProductAffected versions
dropbear_ssh_projectdropbear_ssh<= 2015.71

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-3116