This script is Copyright (C) 1999-2016 Tenable Network Security, Inc.
The remote finger server has an information disclosure vulnerability.
The remote host is running 'cfingerd', a finger daemon.
There is a bug in the remote cfinger daemon that allows a remote
attacker to get the lists of the users of this system when issuing
the command :
This information can be used by a remote attacker to mount further
See also :
There is no known solution at this time. Use another finger daemon,
or disable this service in inetd.conf.
Risk factor :
Medium / CVSS Base Score : 5.0