WatchGuard Firebox MS-CHAPv2 Authentication Remote User Enumeration Weakness
BID:28619
Info
WatchGuard Firebox MS-CHAPv2 Authentication Remote User Enumeration Weakness
| Bugtraq ID: | 28619 |
| Class: | Design Error |
| CVE: |
CVE-2008-1618 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2008 12:00AM |
| Updated: | Apr 08 2008 02:38PM |
| Credit: | Luke Jennings |
| Vulnerable: |
WatchGuard Firebox 0 |
| Not Vulnerable: |
WatchGuard Firebox 10 |
Discussion
WatchGuard Firebox MS-CHAPv2 Authentication Remote User Enumeration Weakness
WatchGuard Firebox is prone to a user-enumeration weakness.
An attacker may leverage this issue to harvest valid usernames, which may aid in brute-force attacks.
Versions prior to WatchGuard Firebox 10 are vulnerable.
WatchGuard Firebox is prone to a user-enumeration weakness.
An attacker may leverage this issue to harvest valid usernames, which may aid in brute-force attacks.
Versions prior to WatchGuard Firebox 10 are vulnerable.
Exploit / POC
WatchGuard Firebox MS-CHAPv2 Authentication Remote User Enumeration Weakness
An attacker can exploit this issue by supplying the device with random usernames.
An attacker can exploit this issue by supplying the device with random usernames.
Solution / Fix
WatchGuard Firebox MS-CHAPv2 Authentication Remote User Enumeration Weakness
Solution:
The vendor has provided an update. Please see the references for more information.
Solution:
The vendor has provided an update. Please see the references for more information.
References
WatchGuard Firebox MS-CHAPv2 Authentication Remote User Enumeration Weakness
References:
References:
- MWR InfoSecurity Advisory Page (MWR InfoSecurit)
- WatchGuard Firebox Product Page (WatchGuard Technologies Inc.)