CVE-2008-0945
Estado: ModificadaBaja (3.5)—
Format string vulnerability in the logging function in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in an IP address field.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P
- Puntuación base: 3.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.88%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-134
Referencias
- http://aluigi.altervista.org/adv/ipsimene-adv.txt
- http://aluigi.org/poc/ipsimene.zip
- http://secunia.com/advisories/28824
- http://securityreason.com/securityalert/3697
- http://www.securityfocus.com/archive/1/487748/100/200/threaded
- http://www.securityfocus.com/bid/27677
- http://aluigi.altervista.org/adv/ipsimene-adv.txt
- http://aluigi.org/poc/ipsimene.zip
- http://secunia.com/advisories/28824
- http://securityreason.com/securityalert/3697
- http://www.securityfocus.com/archive/1/487748/100/200/threaded
- http://www.securityfocus.com/bid/27677
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-0945",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-25T21:44:00.000",
"references": [
{
"url": "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
"source": "cve@mitre.org"
},
{
"url": "http://aluigi.org/poc/ipsimene.zip",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28824",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3697",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/487748/100/200/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27677",
"source": "cve@mitre.org"
},
{
"url": "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://aluigi.org/poc/ipsimene.zip",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28824",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3697",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/487748/100/200/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27677",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-134"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Format string vulnerability in the logging function in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in an IP address field."
},
{
"lang": "es",
"value": "Vulnerabilidad de formato de cadena en la función de inicio de sesión de IM Server (también conocido como IMserve or IMserver) en Ipswitch Instant Messaging (IM) 2.0.8.1 y anteriores permite a usuarios autentificados remotamente provocar una denegación de servicio (caída del demonio) y posiblemente tener otros impactos sin identificar a través de especificadores de formato de cadena en un campo de una dirección IP."
}
],
"lastModified": "2026-06-16T22:50:39.487",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ipswitch:imserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37107C28-9B74-4C67-8A0D-E746647C34FF",
"versionEndIncluding": "2.0.8.1"
},
{
"criteria": "cpe:2.3:a:ipswitch:instant_messaging:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "063110BD-F65A-48F8-BD75-54CA1E370D24",
"versionEndIncluding": "2.0.8.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}