PT-2000-1947 · Check Point · Check Point Firewall-1

Publicado

2000-12-11

·

Atualizado

2008-09-05

·

CVE-2000-1037

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Check Point Firewall-1 session agent versions 3.0 through 4.1
Description The issue allows remote attackers to determine valid usernames and guess a password via a brute force attack, due to different error messages being generated for invalid user names versus invalid passwords.
Recommendations For versions 3.0 through 4.1, consider modifying the error message handling to prevent disclosure of valid usernames, and implement additional security measures such as account lockout policies or rate limiting to mitigate the risk of brute force attacks.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-1037

Produtos afetados

Check Point Firewall-1