PT-2004-3045 · Nettica · Intellipeer Email Server
Published
2004-12-31
·
Updated
2024-02-13
·
CVE-2004-2150
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nettica Corporation INTELLIPEER Email Server version 1.01
Description
The issue allows remote attackers to determine valid account names by exploiting different error messages displayed for valid and invalid account names.
Recommendations
For version 1.01, consider modifying the error message handling to prevent disclosure of valid account names, or update to a version where this issue is resolved if available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intellipeer Email Server