### [CVE-2007-2768](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2768) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243. ### POC #### Reference No PoCs from references. #### Github - https://github.com/phx/cvescan - https://github.com/siddicky/git-and-crumpets - https://github.com/vshaliii/DC-4-Vulnhub-Walkthrough