Description
Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user enumeration and increase the likelihood of targeted brute-force or credential-stuffing attacks.
Problem types
CWE-204 Observable Response Discrepancy
Product status
Any version before 6.40.05
Credits
Alex Williams from Pellera Technologies
References
aggregate.digital/downloads.html
aggregate.digital/products/network-manager.html
www.vulncheck.com/...er-login-functionality-user-enumeration