VulnerabilityModified
CVE-2004-2150
Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names.
MEDIUM 5.0EPSS 2.45%
Does this matter?
Lower severity and a low EPSS score (2.45%). Track it; it rarely justifies an emergency change on its own.
Description
Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.45% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- nettica/intellipeer email server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/12661/Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1011425Broken Link, Third Party Advisory, VDB Entry
- http://www.osvdb.org/10349Broken Link
- http://www.securityfocus.com/bid/11257Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17510Third Party Advisory, VDB Entry
- http://secunia.com/advisories/12661/Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1011425Broken Link, Third Party Advisory, VDB Entry
- http://www.osvdb.org/10349Broken Link
- http://www.securityfocus.com/bid/11257Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17510Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.