The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled, generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.
References
Configurations
History
No history.
Information
Published : 2007-08-18 21:17
Updated : 2017-07-29 01:32
NVD link : CVE-2007-4422
Mitre link : CVE-2007-4422
CVE.ORG link : CVE-2007-4422
JSON object : View
Products Affected
symantec
- enterprise_firewall
CWE