Dropbear is prone to a user enumeration vulnerability (CVE-2018-15599). An external user without credentials can determine whether a given username exists on a server.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2018-0384.json"