vendor:
APOLLO VX20
by:
John Page (hyp3rlinx)
4.1
CVSS
MEDIUM
Account Enumeration
200
CWE
Product Name: APOLLO VX20
Affected Version From: APOLLO VX20 < 1.3.58
Affected Version To: 1.3.1958
Patch Exists: YES
Related CWE: CVE-2024-25734
CPE: h:wyrestorm:apollo_vx20
Platforms Tested:
2024
WyreStorm Apollo VX20 Account Enumeration Vulnerability
An issue in WyreStorm Apollo VX20 devices before 1.3.58 allows attackers to determine valid accounts via the TELNET service, which prompts for a password only after a valid username is entered. This can lead to brute force attacks on valid accounts.
Mitigation:
Update to version 1.3.58 of the firmware to fix the account enumeration vulnerability.