PT-2000-1947 · Check Point · Check Point Firewall-1
Publicado
2000-12-11
·
Atualizado
2008-09-05
·
CVE-2000-1037
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Check Point Firewall-1 session agent versions 3.0 through 4.1
Description
The issue allows remote attackers to determine valid usernames and guess a password via a brute force attack, due to different error messages being generated for invalid user names versus invalid passwords.
Recommendations
For versions 3.0 through 4.1, consider modifying the error message handling to prevent disclosure of valid usernames, and implement additional security measures such as account lockout policies or rate limiting to mitigate the risk of brute force attacks.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Check Point Firewall-1