Skip to main content
E
Echelon
Graph
Product
Directory
Enterprise
Compliance
Pulse
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2024-39894
CVE-2024-39894
High
CVSS
7.5
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g. for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly other timing attacks against keystroke entry could occur.
Vendor
Microsoft Security Response Center (MSRC)
Published
May 31, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2024-39894 →