Inconsistent Error Messages in Check Point VPN-1 4.1SP4 Allows Brute Force Attacks

Inconsistent Error Messages in Check Point VPN-1 4.1SP4 Allows Brute Force Attacks

CVE-2001-1499 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.

Learn more about our User Device Pen Test.