PoC Index

CVE-2005-2640

MEDIUM 5.0EPSS 7.1%

Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
7.09% chance of exploitation in the next 30 days, 94th percentile
Published
2005-08-20
Updated
2024-08-07

ExploitDB entries (1)

References

Related