The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 70.1%