vendor:
H3C SSL VPN
by:
LiquidWorm
4.3
CVSS
MEDIUM
Username Enumeration
200
CWE
Product Name: H3C SSL VPN
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: HttpServer 1.1
2022
H3C SSL VPN – Username Enumeration
The weakness is caused due to the login script and how it verifies provided credentials. An attacker can use this weakness to enumerate valid users on the affected application via 'txtUsrName' POST parameter.
Mitigation:
Ensure that the login script is configured to not reveal valid usernames.