CVE detail
CVE-2020-25200 — CVE-2020-25200
Published 2020-10-01 · Modified 2026-06-17 · Vendor pritunl · Product pritunl · Source nvd
MEDIUM
severity
CVSS-derived band
0.0747
EPSS probability
exploitation probability, 30d
94.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server will start responding with error 400. Invalid usernames will receive error 401 indefinitely. Note: This has been disputed by the vendor as not a vulnerability. They argue that this is an intended design
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References