First published: Mon Apr 07 2008(Updated: )
The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Watchguard Firebox Pptp Vpn | =5.0 | |
Watchguard Firebox Pptp Vpn | =4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.