CVE-2019-13599: Medium severity centos web panel vulnerability
Published Aug 21, 2019
·Updated
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.848
Event History
Aug 21, 2019
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13599?
CVE-2019-13599 is considered a medium severity vulnerability that allows user enumeration.
2
How do I fix CVE-2019-13599?
To fix CVE-2019-13599, implement rate limiting in the login process to mitigate the response time discrepancy.
3
What is the impact of CVE-2019-13599?
The impact of CVE-2019-13599 is that attackers can determine valid usernames through timing analysis.
4
Which version of CWP is affected by CVE-2019-13599?
CVE-2019-13599 specifically affects CentOS Web Panel version 0.9.8.848.
5
Is user enumeration a common issue found in applications like CVE-2019-13599?
Yes, user enumeration vulnerabilities like CVE-2019-13599 are common and can lead to account enumeration and potential brute force attacks.