vendor:
APOLLO VX20
by:
John Page (aka hyp3rlinx)
4.1
CVSS
MEDIUM
Account Enumeration
200
CWE
Product Name: APOLLO VX20
Affected Version From: APOLLO VX20 - < 1.3.58
Affected Version To: 21245
Patch Exists: YES
Related CWE: CVE-2024-25734
CPE: a:wyrestorm:apollo_vx20:1.3.57
Platforms Tested:
2024
WyreStorm APOLLO VX20 Account Enumeration Vulnerability
WyreStorm Apollo VX20 devices before version 1.3.58 are vulnerable to an account enumeration issue where the TELNET service prompts for a password only after a valid username is entered. Attackers who can access the Telnet service can identify valid accounts, potentially leading to brute force attacks on valid accounts.
Mitigation:
Upgrade to version 1.3.58 or newer to mitigate this account enumeration vulnerability in WyreStorm APOLLO VX20 devices.