Vulnerability Name: | CVE-2001-1499 (CCN-7343) | ||||||||
Assigned: | 2001-10-23 | ||||||||
Published: | 2001-10-23 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Oct 23 2001 - 16:07:05 CDT Check Point VPN-1 SecuRemote Flaw Source: MITRE Type: CNA CVE-2001-1499 Source: OSVDB Type: UNKNOWN 20210 Source: CCN Type: OSVDB ID: 20210 Check Point VPN-1 SecuRemote Error Message Account Enumeration Source: BUGTRAQ Type: UNKNOWN 20011023 Check Point VPN-1 SecuRemote Flaw Source: BUGTRAQ Type: UNKNOWN 20011024 RE: Check Point VPN-1 SecuRemote Flaw Source: BID Type: UNKNOWN 3470 Source: CCN Type: BID-3470 Check Point VPN-1 SecuRemote Username Acknowledgement Vulnerability Source: XF Type: UNKNOWN vpn1-securemote-brute-force(7343) Source: XF Type: UNKNOWN vpn1-securemote-brute-force(7343) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |