VulnerabilityModified
CVE-2001-1499
Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.
MEDIUM 5.0EPSS 1.52%
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- checkpoint/vpn-1
- Source
- cve@mitre.org
References
- http://www.osvdb.org/20210
- http://www.securityfocus.com/archive/1/222366
- http://www.securityfocus.com/archive/1/222479
- http://www.securityfocus.com/bid/3470
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7343
- http://www.osvdb.org/20210
- http://www.securityfocus.com/archive/1/222366
- http://www.securityfocus.com/archive/1/222479
- http://www.securityfocus.com/bid/3470
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7343
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.