Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts.
CPE | Name | Operator | Version |
---|---|---|---|
lighthouse_sms | le | 5.1 |