Tollgrade LightHouse SMS prior to 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote malicious users to enumerate account names via a series of attempts.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
tollgrade lighthouse sms |