Unrated severityNVD Advisory· Published Apr 7, 2008· Updated Apr 23, 2026
CVE-2008-1618
CVE-2008-1618
Description
The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
Affected products
2cpe:2.3:a:watchguard:firebox_pptp_vpn:4.9:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:watchguard:firebox_pptp_vpn:4.9:*:*:*:*:*:*:*
- cpe:2.3:a:watchguard:firebox_pptp_vpn:5.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.mwrinfosecurity.com/publications/mwri_watchguard-firebox-pptp-vpn-user-enumeration-advisory_2008-04-04.pdfnvdExploitPatch
- secunia.com/advisories/29708nvdVendor Advisory
- www.vupen.com/english/advisories/2008/1152/referencesnvdVendor Advisory
- www.osvdb.org/44218nvd
- www.securityfocus.com/bid/28619nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/41683nvd
News mentions
0No linked articles in our index yet.