CVE-2005-2640
published 2005-08-23CVE-2005-2640: Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows…
PriorityP432medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
7.09%
93.5th percentile
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
Affected
130 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | netscreen-5gt | — | — |
| juniper | netscreen-idp | — | — |
| juniper | netscreen-idp | — | — |
| juniper | netscreen-idp | — | — |
| juniper | netscreen-idp_10 | — | — |
| juniper | netscreen-idp_100 | — | — |
| juniper | netscreen-idp_1000 | — | — |
| juniper | netscreen-idp_500 | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
| juniper | netscreen_screenos | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8h6v-vg4c-567j: Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5
ghsa_unreviewed·2022-05-01
CVE-2005-2640 [MEDIUM] GHSA-8h6v-vg4c-567j: Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
Juniper
CVE-2005-2640: Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication
vendor_juniper·2005-08-23·CVSS 5.0
CVE-2005-2640 [MEDIUM] CVE-2005-2640: Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication
CVE-2005-2640: Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
No detection rules found.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=112438068426034&w=2http://secunia.com/advisories/16474/http://securitytracker.com/id?1014728http://www.nta-monitor.com/news/vpn-flaws/juniper/netscreen/index.htmhttp://www.securityfocus.com/bid/14595http://marc.info/?l=bugtraq&m=112438068426034&w=2http://secunia.com/advisories/16474/http://securitytracker.com/id?1014728http://www.nta-monitor.com/news/vpn-flaws/juniper/netscreen/index.htmhttp://www.securityfocus.com/bid/14595
2005-08-23
Published