cbcvebase.
CVE-2005-2640
published 2005-08-23

CVE-2005-2640: Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows…

PriorityP432medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
7.09%
93.5th percentile
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.

Affected

130 ranges· showing 25
VendorProductVersion rangeFixed in
junipernetscreen-5gt
junipernetscreen-idp
junipernetscreen-idp
junipernetscreen-idp
junipernetscreen-idp_10
junipernetscreen-idp_100
junipernetscreen-idp_1000
junipernetscreen-idp_500
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
junipernetscreen_screenos
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.