CVE Vulnerabilities

CVE-2000-1032

Published: Dec 11, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.

Affected Software

Name Vendor Start Version End Version
Firewall-1 Checkpoint 3.0 (including) 3.0 (including)
Firewall-1 Checkpoint 4.0 (including) 4.0 (including)

References