Impact
Rejetto HFS versions 3.0.0 through 3.2.0 leak information through observable differences in the login endpoint – whether the supplied username exists can be determined by an unauthenticated remote user, enabling the enumeration of valid account names, including the default admin account. This flaw, classified as CWE‑204, can lead to password‑guessing attacks and session‑forgery because an attacker can target discovered usernames with brute‑force or credential‑stuffing techniques.
Affected Systems
The vulnerability affects the Rejetto HFS web server product, specifically all releases from 3.0.0 up to and including 3.2.0. Systems running these releases are vulnerable unless updated to version 3.2.1 or later, where the issue has been fixed.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score of less than 1% suggests a very low exploitation probability, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation. The likely attack vector is a remote, unauthenticated web attacker who can interact with the login endpoint over the network. While exploitation requires only network access, the lack of a readily available public exploit and the low EPSS indicate that the threat level remains moderate but still important for exposed deployments.
OpenCVE Enrichment