← Vulnerability feed

Vulnerability record · CVE-1999-1231 · published 9 June 1999

CVE-1999-1231: Ssh2 vulnerability

Ssh · Ssh2

ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

5.0 CVSS 2.0 Medium EPSS 1.5% · top 27.4%
5.0CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-1231 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-1645Ssh2 vulnerabilityBuffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary cod…EPSS 7.9%7.5CVE-1999-1029Ssh2 vulnerabilitySSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a r…EPSS 1.6%7.2CVE-2002-1715Ssh vulnerabilitySSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-w…EPSS 0.89%7.2CVE-2002-1644Ssh2 vulnerabilitySSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove t…EPSS 0.45%5.1CVE-2000-0217Openbsd openssh vulnerabilityThe default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth prog…EPSS 0.97%5.0CVE-2001-0364Ssh2 vulnerabilitySSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.EPSS 1.6%4.6CVE-1999-0398Ssh vulnerabilityIn some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.EPSS 0.39%4.6CVE-1999-1159Ssh2 vulnerabilitySSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-1999-1231), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.