CVE Vulnerabilities

CVE-2008-0640

Improper Authentication

Published: Feb 08, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Ghost_solutions_suiteSymantec1.1 (including)1.1 (including)
Ghost_solutions_suiteSymantec2.0.0 (including)2.0.0 (including)
Ghost_solutions_suiteSymantec2.0.1 (including)2.0.1 (including)

Potential Mitigations

References