CVE-2008-0640
Estado: ModificadaAlta (10)—
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.93%
- Percentil entre todas las CVEs puntuadas: 87
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
- http://secunia.com/advisories/28853
- http://www.securityfocus.com/bid/27644
- http://www.securitytracker.com/id?1019356
- http://www.symantec.com/avcenter/security/Content/2008.02.07.html
- http://www.vupen.com/english/advisories/2008/0474
- http://secunia.com/advisories/28853
- http://www.securityfocus.com/bid/27644
- http://www.securitytracker.com/id?1019356
- http://www.symantec.com/avcenter/security/Content/2008.02.07.html
- http://www.vupen.com/english/advisories/2008/0474
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-0640",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-08T02:00:00.000",
"references": [
{
"url": "http://secunia.com/advisories/28853",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27644",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1019356",
"source": "cve@mitre.org"
},
{
"url": "http://www.symantec.com/avcenter/security/Content/2008.02.07.html",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0474",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28853",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27644",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1019356",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/avcenter/security/Content/2008.02.07.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0474",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing."
},
{
"lang": "es",
"value": "Symantec Ghost Solution Suite versión 1.1 anterior a 1.1 parche 2, versiones 2.0.0 y 2.0.1 no autentica las conexiones entre la consola y Ghost Management Agent, lo que permite a los atacantes remotos ejecutar comandos arbitrarios por medio de peticiones RPC no especificadas en conjunto con suplantación de ARP."
}
],
"lastModified": "2026-06-16T22:50:02.620",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:ghost_solutions_suite:1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A66AA7A-B410-45E8-8BB0-1F349BB30422"
},
{
"criteria": "cpe:2.3:a:symantec:ghost_solutions_suite:2.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27FA37CC-D408-4213-8A3F-C46C97008E33"
},
{
"criteria": "cpe:2.3:a:symantec:ghost_solutions_suite:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFEA8748-EE69-4803-96B1-9359F45022C7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}