>> Watchguard Firebox X Remote VPN User Enumeration Weakness
Title : Watchguard Firebox X Remote VPN User Enumeration Weakness VUPEN ID : VUPEN/ADV-2008-1152 CVE ID : CVE-2008-1618
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-09
Technical Description
A weakness has been identified in WatchGuard Firebox products, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused by an error in the PPTP VPN service that sends different responses to valid and invalid usernames supplied via MS-CHAPv2 packets, which could be exploited by remote unauthenticated attackers to determine if a guessed username is valid.