CVE-2008-0640
Summary
| CVE | CVE-2008-0640 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-02-08 02:00:00 UTC |
| Updated | 2011-07-25 04:00:00 UTC |
| Description | Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Ghost Solutions Suite | 1.1 | All | All | All |
| Application | Symantec | Ghost Solutions Suite | 2.0.0 | All | All | All |
| Application | Symantec | Ghost Solutions Suite | 2.0.1 | All | All | All |
| Application | Symantec | Ghost Solutions Suite | 1.1 | All | All | All |
| Application | Symantec | Ghost Solutions Suite | 2.0.0 | All | All | All |
| Application | Symantec | Ghost Solutions Suite | 2.0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Symantec Ghost Solution Suite Client Command Execution Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| 404 Not Found | CONFIRM | www.symantec.com | Patch |
| Symantec Ghost Solution Suite ARP Spoofing Authentication Bypass Vulnerability | BID | www.securityfocus.com | |
| SecurityTracker.com Archives - Symantec Ghost Solution Suite Authentication Bug Lets Remote Users Execute Arbitrary Code | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.