CVE-1999-1231: ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times
Summary
ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.
Severity
UNKNOWN
Source Attribution
Source: NVD · Updated: 2026-08-21T04:30:46.969Z · Confidence: high
Impact
Based on CVSS vector: n/a — assess confidentiality, integrity, and availability impact via the official vector documentation.
Affected Software
Fix
Upgrade affected software to the fixed version identified above. Apply vendor patches and monitor advisories before exposed systems go unpatched.