Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pw7-5gjq-98f6

Опубликовано: 23 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user enumeration and increase the likelihood of targeted brute-force or credential-stuffing attacks.

Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user enumeration and increase the likelihood of targeted brute-force or credential-stuffing attacks.

EPSS

Процентиль: 59%
0.00375
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-204

Связанные уязвимости

nvd
4 месяца назад

Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user enumeration and increase the likelihood of targeted brute-force or credential-stuffing attacks.

EPSS

Процентиль: 59%
0.00375
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-204