CVE-2015-7680: Infoleak
Published Feb 10, 2016
·Updated
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.
Affected Software
1 affected component
IPSwitch MOVEit DMZ<=8.1
Event History
Feb 10, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7680?
CVE-2015-7680 is considered a medium severity vulnerability due to the risk of username enumeration.
2
How do I fix CVE-2015-7680?
To fix CVE-2015-7680, upgrade to Ipswitch MOVEit DMZ version 8.2 or newer.
3
What is the impact of CVE-2015-7680?
The impact of CVE-2015-7680 allows remote attackers to potentially enumerate valid usernames.
4
Which versions of Ipswitch MOVEit DMZ are affected by CVE-2015-7680?
CVE-2015-7680 affects Ipswitch MOVEit DMZ versions prior to 8.2.
5
What is the nature of the vulnerability in CVE-2015-7680?
The vulnerability in CVE-2015-7680 is based on differing error messages that reveal information about user accounts.