CVE Vulnerabilities

CVE-2008-0640

Improper Authentication

Published: Feb 08, 2008 | Modified: Jul 25, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Ghost_solutions_suite Symantec 1.1 (including) 1.1 (including)
Ghost_solutions_suite Symantec 2.0.0 (including) 2.0.0 (including)
Ghost_solutions_suite Symantec 2.0.1 (including) 2.0.1 (including)

Potential Mitigations

References