Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pv8j-6vmm-x69g

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.

The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.

EPSS

Процентиль: 69%
0.0061
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 18 лет назад

The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.

EPSS

Процентиль: 69%
0.0061
Низкий

Дефекты

CWE-200