CVE-2008-4315
Summary
| CVE | CVE-2008-4315 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-27 00:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openpegasus | Openpegasus Wbem | 2.7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5.0 | All | server | All |
| Operating System | Redhat | Enterprise Linux Desktop | 5.0 | All | client | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/50278 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| admin.fedoraproject.org/updates/tog-pegasus-2.7.1-3.fc10 | af854a3a-2127-422b-91ae-364da2661108 | admin.fedoraproject.org | |
| admin.fedoraproject.org/updates/tog-pegasus-2.7.0-7.fc9 | af854a3a-2127-422b-91ae-364da2661108 | admin.fedoraproject.org | |
| Red Hat update for tog-pegasus - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 472017 – (CVE-2008-4315) CVE-2008-4315 tog-pegasus: failed authentication attempts not logged via PAM | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| OpenPegasus Does Not Log Failed Authentication Attempts - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.