← Vulnerability feed

Vulnerability record · CVE-2005-2640 · published 23 August 2005

CVE-2005-2640: Neoteris instant virtual extranet vulnerability

NNeoteris · Instant Virtual Extranet

Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.

5.0 CVSS 2.0 Medium EPSS 7.1% · top 6.0%
5.0CVSS 2.0 base score
7.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
16Affected product versions listed by NVD
10References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2640 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.4CVE-2018-0059Juniper netscreen screenos cross-site scripting vulnerabilityA persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web scrip…EPSS 0.80%5.0CVE-2004-1446Juniper netscreen screenos vulnerabilityUnknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device…EPSS 3.1%5.0CVE-2002-1547Juniper netscreen screenos vulnerabilityNetscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command …EPSS 3.5%5.0CVE-2002-2150Juniper netscreen screenos vulnerabilityFirewalls from multiple vendors empty state tables more slowly than they are filled, which allows remote attackers to flood state tables with packet …EPSS 2.0%5.0CVE-2002-0891Juniper netscreen screenos vulnerabilityThe web interface (WebUI) of NetScreen ScreenOS before 2.6.1r8, and certain 2.8.x and 3.0.x versions before 3.0.3r1, allows remote attackers to cause…EPSS 1.6%4.3CVE-2008-6096Juniper netscreen screenos cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject arbitrary we…EPSS 1.0%2.1CVE-2002-0234Juniper netscreen screenos vulnerabilityNetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted networ…EPSS 0.35%2.1CVE-2001-0589Juniper netscreen screenos vulnerabilityNetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific tra…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2005-2640), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.