Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.
No PoCs from references.
- https://github.com/CiscoCXSecurity/ownCloud_RCE_CVE-2013-0303
- https://github.com/steponequit/CVE-2013-1081
- https://github.com/styx00/Dropbear_CVE-2013-4434