Synced 17 Jun 2026 22:27 UTC Account
← All products

CVE-2011-0766

HIGH severity · CVSS 7.8 · CWE-310
7.8CVSS HIGH

Summary

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges required
User interaction
Confidentiality impact
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)3%

AV:N/AC:L/Au:N/C:C/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: http://www.kb.cert.org/vuls/id/178990 ↗