5

CVE-2008-1618

Exploit
The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WatchguardFirebox Pptp Vpn Version4.9
WatchguardFirebox Pptp Vpn Version5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.74% 0.748
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://secunia.com/advisories/29708
Vendor Advisory
http://www.mwrinfosecurity.com/publications/mwri_watchguard-firebox-pptp-vpn-user-enumeration-advisory_2008-04-04.pdf
Patch
Exploit
http://www.osvdb.org/44218
http://www.securityfocus.com/bid/28619
http://www.securitytracker.com/id?1019796
http://www.vupen.com/english/advisories/2008/1152/references
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/41683