SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-2640

Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which…

MEDIUM 5.0EPSS 7.09%

Does this matter?

Lower severity and a low EPSS score (7.09%). Track it; it rarely justifies an emergency change on its own.

Description

Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
7.09% probability · 94th percentile
CISA KEV
Not listed
Affected
neoteris/instant virtual extranet · juniper/netscreen screenos · netscreen/ns-10 · netscreen/ns-100 · netscreen/ns-204 · netscreen/ns-500 · netscreen/ns-50ns25 · juniper/netscreen-5gt · juniper/netscreen-idp · juniper/netscreen-idp 10 · juniper/netscreen-idp 100 · juniper/netscreen-idp 1000 · juniper/netscreen-idp 500 · netscreen/netscreen-sa 5000 series · netscreen/netscreen-sa 5020 series · netscreen/netscreen-sa 5050 series
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.