Описание
Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames".
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:tufin:securetrack:*:*:*:*:*:*:*:*
EPSS
Процентиль: 23%
0.00076
Низкий
4.3 Medium
CVSS3
3.3 Low
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
github
больше 3 лет назад
Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames".
EPSS
Процентиль: 23%
0.00076
Низкий
4.3 Medium
CVSS3
3.3 Low
CVSS2
Дефекты
NVD-CWE-noinfo