Intellipeer User Account Enumeration

medium Nessus Network Monitor Plugin ID 2332

Synopsis

The remote host may give an attacker information useful for future attacks.

Description

The remote host is running a POP3 service that allows a remote attacker to determine when a user account is valid. An attacker exploiting this flaw would only need to connect to the port repeatedly while sending different user names. The server will alert the attacker whenever a valid username is sent. This vulnerability is known to affect Intellipeer POP3 server (versions less than or equal to 1.0.1).

Solution

Upgrade or patch according to vendor recommendations.

See Also

http://www.nettica.com/Downloads/Default.aspx

Plugin Details

Severity: Medium

ID: 2332

Family: POP Server

Published: 9/27/2004

Updated: 3/6/2019

Nessus ID: 14829

Risk Information

VPR

Risk Factor: Low

Score: 2.5

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:H/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:nettica_corporation:intellipeer_email_server

Reference Information

CVE: CVE-2004-2150

BID: 11257