The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.mwrinfosecurity.com/publications/mwri_watchguard-firebox-pptp-vpn-user-enumeration-advisory_2008-04-04.pdf | patch exploit |
http://www.osvdb.org/44218 | vdb entry |
http://www.vupen.com/english/advisories/2008/1152/references | vdb entry vendor advisory |
http://www.securityfocus.com/bid/28619 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41683 | vdb entry |
http://secunia.com/advisories/29708 | third party advisory vendor advisory |
http://www.securitytracker.com/id?1019796 | vdb entry |