Security Advisory

CVE-2017-8055

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-04-22 22:00:00
Last updated 2024-09-16 19:24:27
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usernames. An attacker could exploit this vulnerability to enumerate valid usernames on an affected Firebox.