CVE-2005-2640
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which…
Does this matter?
Lower severity and a low EPSS score (7.09%). Track it; it rarely justifies an emergency change on its own.
Description
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.09% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- neoteris/instant virtual extranet · juniper/netscreen screenos · netscreen/ns-10 · netscreen/ns-100 · netscreen/ns-204 · netscreen/ns-500 · netscreen/ns-50ns25 · juniper/netscreen-5gt · juniper/netscreen-idp · juniper/netscreen-idp 10 · juniper/netscreen-idp 100 · juniper/netscreen-idp 1000 · juniper/netscreen-idp 500 · netscreen/netscreen-sa 5000 series · netscreen/netscreen-sa 5020 series · netscreen/netscreen-sa 5050 series
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=112438068426034&w=2
- http://secunia.com/advisories/16474/Vendor Advisory
- http://securitytracker.com/id?1014728
- http://www.nta-monitor.com/news/vpn-flaws/juniper/netscreen/index.htmExploit, Vendor Advisory
- http://www.securityfocus.com/bid/14595Exploit
- http://marc.info/?l=bugtraq&m=112438068426034&w=2
- http://secunia.com/advisories/16474/Vendor Advisory
- http://securitytracker.com/id?1014728
- http://www.nta-monitor.com/news/vpn-flaws/juniper/netscreen/index.htmExploit, Vendor Advisory
- http://www.securityfocus.com/bid/14595Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.