PT-2001-2584 · Check Point · Check Point Vpn-1
Published
2001-12-31
·
Updated
2017-07-11
·
CVE-2001-1499
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Check Point VPN-1 version 4.1SP4
Description
The issue allows remote attackers to more easily conduct brute force attacks due to the different error messages returned for valid and invalid users. This variation in error messages depends on the authentication method being used.
Recommendations
For Check Point VPN-1 version 4.1SP4, consider implementing additional authentication measures or rate limiting to mitigate the risk of brute force attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Check Point Vpn-1