Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-4422

EPSS 2.51% · P85
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-4422

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled, generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Symantec企业防火墙用户名枚举漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Symantec Enterprise Firewall(SEP)是一个高性能防火墙解决方案,适用于WINDOWS和SOLARIS操作系统。 SEP在处理某种认证请求时存在漏洞,远程攻击者可能利用此漏洞暴力猜测有效的用户名。 如果对Symantec企业防火墙配置了使用预共享密钥(PSK)认证的远程访问(客户端到网关)VPN的话,就会对有效和无效用户名提供不同的响应。这就允许攻击者判断所猜测的用户名是否有效,但不会列出有效的用户名,仅可以确定所提供的用户名是否存在。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-4422

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-4422

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-08-18 · 35 CVEs total

CVE-2007-4415Windows平台的Cisco VPN客户端多个本地权限提升漏洞
CVE-2007-4407Universal Ircd Server 多个远程漏洞
CVE-2007-4408ircu 多个远程漏洞
CVE-2007-4409ircu 竞争状态错误漏洞
CVE-2007-4410Universal Ircd Server 多个远程漏洞
CVE-2007-4411Universal Ircd Server 多个远程漏洞
CVE-2007-4412Headstart Solutions DeskPRO 多个跨站脚本攻击漏洞
CVE-2007-4413Headstart Solutions DeskPRO'admincp/user_help.php'直接静态代码注入漏洞
CVE-2007-4414Windows平台的Cisco VPN客户端多个本地权限提升漏洞
CVE-2007-4406ircu timestamp服务 权限提升漏洞
CVE-2007-4416BellaBook'captcha.php'权限提升漏洞
CVE-2007-4417IBM DB2 UDB Fixpak配置错误漏洞
CVE-2007-4418IBM DB2 UDB Fixpak 检测权限管理漏洞
CVE-2007-4419Olate Download 'Admin.php'cookie信息泄露漏洞
CVE-2007-4420EDraw Office Viewer 组件 officeviewer.ocx ActiveX控件绝对路径遍历漏洞
CVE-2007-4421Olate Download'Admin.php'SQL注入漏洞
CVE-2007-4423IBM DB2 UDB AUTH_LIST_GROUPS_FOR_AUTHID函数未明漏洞
CVE-2007-4398weechat 脚本now-playing.rb和 xmms.pl多个CRLF注入漏洞
CVE-2007-4270IBM DB2 Universal Database本地用户权限提升漏洞
CVE-2007-4271IBM DB2 Universal Database目录遍历漏洞

Showing top 20 of 35 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-4422

No comments yet


Leave a comment