Timing difference in password reset in Ergon Informatik AG's Airlock...
Vulnerability Description
Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackers to enumerate usernames.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6056
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Patrick Schlüter - Redguard AG
Affected Vendor
Ergon Informatik AG
View all reports →