Back to search
CVE-2005-2640
Published: Aug 20, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
14595
vdb-entry
x_refsource_BID
20050818 Juniper Netscreen VPN Username Enumeration Vulnerability
mailing-list
x_refsource_BUGTRAQ
1014728
vdb-entry
x_refsource_SECTRACK
16474
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now