DualShield 5.9.8.0821 allows username enumeration on its login form. A valid username results in prompting for the password, whereas an invalid one will produce an "unknown username" error message.
Link | Tags |
---|---|
https://deepnetsecurity.com/multi-factor-authentication/ | vendor advisory |
https://excellium-services.com/cert-xlm-advisory/CVE-2020-28918 | third party advisory |