CVE-2008-1618
The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
- Affected products
- Watchguard Firebox
- Watchguard Firebox Pptp Vpn
- = 4.9, 5.0
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2008-04-07
CVE-2008-1618 at NVD
No indexed exploits for CVE-2008-1618 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2008-1618 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.