Tracker / CVE-2005-2640
CVE-2005-2640
Medium 5.0
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
Affected products and versions
| juniper | netscreen-5gt |
|---|---|
| juniper | netscreen-idp |
| juniper | netscreen-idp_10 |
| juniper | netscreen-idp_100 |
| juniper | netscreen-idp_1000 |
| juniper | netscreen-idp_500 |
| juniper | netscreen_screenos |
| neoteris | instant_virtual_extranet |
| netscreen | netscreen-sa_5000_series |
| netscreen | netscreen-sa_5020_series |
| netscreen | netscreen-sa_5050_series |
| netscreen | ns-10 |
| netscreen | ns-100 |
| netscreen | ns-204 |
| netscreen | ns-500 |
| netscreen | ns-50ns25 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.