CVE-2008-1618: Infoleak
The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1618?
CVE-2008-1618 is classified as a medium severity vulnerability that allows remote attackers to perform username enumeration.
How do I fix CVE-2008-1618?
To mitigate CVE-2008-1618, it is recommended to upgrade Watchguard Firebox to the latest version or apply any available patches.
Which versions are affected by CVE-2008-1618?
CVE-2008-1618 affects Watchguard Firebox PPTP VPN versions prior to 10, specifically 4.9 and 5.0.
What type of attack does CVE-2008-1618 allow?
CVE-2008-1618 allows remote attackers to enumerate valid usernames through the MS-CHAPv2 authentication handshake error code responses.
Is there a workaround for CVE-2008-1618?
Disabling the PPTP VPN service on affected Watchguard Firebox devices can serve as a temporary workaround for CVE-2008-1618.