CVE-2024-44762: Medium severity usermin vulnerability
Published Oct 16, 2024
·Updated
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.
Affected Software
2 affected components
Webmin Usermin
Webmin Usermin=2.100
Event History
Oct 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Apr 3, 2025
Exploit Published
12:00 AM
Known Exploited
01:45 PM
Apr 17, 2025
Exploit Published
12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-44762?
CVE-2024-44762 is considered a medium severity vulnerability as it allows attackers to enumerate valid user accounts.
2
How do I fix CVE-2024-44762?
To fix CVE-2024-44762, update to the latest version of Webmin Usermin that addresses this error message discrepancy.
3
How does CVE-2024-44762 affect Webmin Usermin?
CVE-2024-44762 affects Webmin Usermin by allowing attackers to exploit incorrect error messages to discover valid user accounts.
4
Who is affected by CVE-2024-44762?
All users of Webmin Usermin v2.100 are affected by CVE-2024-44762 due to the enumeration issue.
5
What can attackers do with CVE-2024-44762?
Attackers can use CVE-2024-44762 to enumerate valid user accounts, potentially leading to further attacks on the system.