Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2016-07-15T16:00:00
Updated: 2024-08-06T01:15:09.045Z
Reserved: 2016-06-23T00:00:00
Link: CVE-2016-5797
Vulnrichment
No data.
NVD
Status : Modified
Published: 2016-07-15T16:59:13.393
Modified: 2024-11-21T02:55:01.667
Link: CVE-2016-5797
Redhat
No data.