First published: Mon Dec 31 2001(Updated: )
Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Check Point VPN-1 | =4.1-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1499 is considered a medium severity vulnerability due to its potential for enabling brute force attacks.
To fix CVE-2001-1499, consider upgrading to a later version of Check Point VPN-1 that addresses this issue.
CVE-2001-1499 can enable remote attackers to conduct brute force attacks on user credentials.
CVE-2001-1499 specifically affects Check Point VPN-1 version 4.1 SP4.
Yes, CVE-2001-1499 highlights that the varying error messages depend on the authentication method used, providing hints to attackers.