MEDIUM · 5.0

CVE-2005-2640

Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usern...

Vulnerability Description

Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NeoterisInstant Virtual Extranet3.0
JuniperNetscreen Screenos1.7
NetscreenNs-10All versions
NetscreenNs-1003.0_.pe1.0
NetscreenNs-2045.0.0_r6.0
NetscreenNs-5004110.0_11_4.0_r10.0
NetscreenNs-50Ns255.0.0_r6.0
JuniperNetscreen-5Gt5.0
JuniperNetscreen-Idp3.0
JuniperNetscreen-Idp 103.0.1_r1
JuniperNetscreen-Idp 1003.0.1_r1
JuniperNetscreen-Idp 10003.0.1_r1
JuniperNetscreen-Idp 5003.0.1_r1
NetscreenNetscreen-Sa 5000 SeriesAll versions
NetscreenNetscreen-Sa 5020 Series4.2_r2.2
NetscreenNetscreen-Sa 5050 Series4.2_r2.2

References

FAQ

What is CVE-2005-2640?

CVE-2005-2640 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usern...

How severe is CVE-2005-2640?

CVE-2005-2640 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2640?

Check the references section above for vendor advisories and patch information. Affected products include: Neoteris Instant Virtual Extranet, Juniper Netscreen Screenos, Netscreen Ns-10, Netscreen Ns-100, Netscreen Ns-204.