The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled, generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.
References
Configurations
Information
Published : 2007-08-18 14:17
Updated : 2017-07-28 18:32
NVD link : CVE-2007-4422
Mitre link : CVE-2007-4422
JSON object : View
CWE
Products Affected
symantec
- enterprise_firewall