CVE-2017-8055
22.04.2017, 22:59
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usernames. An attacker could exploit this vulnerability to enumerate valid usernames on an affected Firebox.Enginsight
Vendor | Product | Version |
---|---|---|
watchguard | fireware | 𝑥 ≤ 11.2.1 |
𝑥
= Vulnerable software versions
References