5
CVSSv2

CVE-2007-0195

Published: 12/01/2007 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

my.activation.php3 in F5 FirePass 5.4 up to and including 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote malicious users to confirm the validity of an LDAP account.

Vulnerable Product Search on Vulmon Subscribe to Product

f5 firepass 5.4.1

f5 firepass 5.4.6

f5 firepass 5.4.8

f5 firepass 5.4.2

f5 firepass 5.4.3

f5 firepass 5.4.4

f5 firepass 5.4.5

f5 firepass 5.5

f5 firepass 5.5.1

f5 firepass 6.0

f5 firepass 5.4

f5 firepass 5.4.7

f5 firepass 5.4.9