5
CVSSv2

CVE-2015-7680

Published: 10/02/2016 Updated: 18/02/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Ipswitch MOVEit DMZ prior to 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote malicious users to enumerate usernames via a series of SOAP requests to machine.aspx.

Vulnerable Product Search on Vulmon Subscribe to Product

ipswitch moveit dmz

Exploits

Ipswitch MOVEit DMZ versions 81 and below suffer from an information disclosure vulnerability ...