CVE Vulnerabilities

CVE-2000-1032

Published: Dec 11, 2000 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.

Affected Software

Name Vendor Start Version End Version
Firewall-1 Checkpoint 3.0 (including) 3.0 (including)
Firewall-1 Checkpoint 4.0 (including) 4.0 (including)

References