CVE-2000-1032

UnknownEPSS 1.81%

Last modified

CVE-2000-1032 is a vulnerability of currently unknown severity. The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.. EPSS estimates a 1.81% chance of exploitation in the next 30 days.

Description

The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.

Metrics

EPSS Probability
1.81%

75.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CheckpointFirewall-13.0
CheckpointFirewall-14.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2000-1032?
The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.
How severe is CVE-2000-1032?
Severity scoring for CVE-2000-1032 is pending analysis. The EPSS model estimates a 1.81% probability of exploitation in the next 30 days.
How do I fix CVE-2000-1032?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2000-1032?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST