Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-25200

Опубликовано: 01 окт. 2020
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Средний

Описание

Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server will start responding with error 400. Invalid usernames will receive error 401 indefinitely. Note: This has been disputed by the vendor as not a vulnerability. They argue that this is an intended design

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pritunl:pritunl:1.29.2145.25:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.62652
Средний

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server will start responding with error 400. Invalid usernames will receive error 401 indefinitely.

EPSS

Процентиль: 98%
0.62652
Средний

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-203