Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 24 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tibbo
Tibbo aggregate |
|
| Vendors & Products |
Tibbo
Tibbo aggregate |
Thu, 23 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user enumeration and increase the likelihood of targeted brute-force or credential-stuffing attacks. | |
| Title | Tibbo AggreGate Network Manager < 6.40.05 Login Functionality User Enumeration | |
| Weaknesses | CWE-204 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-10-23T16:40:02.865Z
Reserved: 2025-04-15T19:15:22.565Z
Link: CVE-2025-34155
Updated: 2025-10-23T16:39:57.684Z
Status : Received
Published: 2025-10-23T17:15:36.720
Modified: 2025-10-23T17:15:36.720
Link: CVE-2025-34155
No data.
OpenCVE Enrichment
Updated: 2025-10-24T10:16:55Z