CVE-2008-1618
07.04.2008, 18:44
The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.Enginsight
| Vendor | Product | Version |
|---|---|---|
| watchguard | firebox_pptp_vpn | 4.9 |
| watchguard | firebox_pptp_vpn | 5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References