Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
7.7.9 (custom)
affected
8.0.8 (custom)
affected
8.1.7 (custom)
affected
8.2.4 (custom)
affected
8.3.1 (custom)
affected
8.4.1 (custom)
unaffected
Description
Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackers to enumerate usernames.
Problem types
CWE-203 Observable Discrepancy
Product status
7.7.9 (custom)
8.0.8 (custom)
8.1.7 (custom)
8.2.4 (custom)
8.3.1 (custom)
8.4.1 (custom)
Credits
Patrick Schlüter - Redguard AG
References
www.redguard.ch/...25-6056-airlock-iam-username-enumeration/