First published: Wed Dec 01 2004(Updated: )
Nortel Networks Contivity VPN Client displays a different error message depending on whether the username is valid or invalid, which could allow remote attackers to gain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nortel Contivity | =4.91 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1105 is considered a moderate security vulnerability due to its potential for information disclosure.
To mitigate CVE-2004-1105, update the Nortel Networks Contivity VPN Client to a version that resolves this issue.
CVE-2004-1105 may expose whether a username is valid or invalid, leading to sensitive information disclosure.
Users of Nortel Networks Contivity VPN Client version 4.91 are specifically affected by CVE-2004-1105.
Yes, CVE-2004-1105 can be exploited by remote attackers who can send requests to the vulnerable client.