CVE-2008-0640
Status: ModifiedHigh (10)—
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.93%
- Percentile among all scored CVEs: 87
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-287
References
- http://secunia.com/advisories/28853
- http://www.securityfocus.com/bid/27644
- http://www.securitytracker.com/id?1019356
- http://www.symantec.com/avcenter/security/Content/2008.02.07.html
- http://www.vupen.com/english/advisories/2008/0474
- http://secunia.com/advisories/28853
- http://www.securityfocus.com/bid/27644
- http://www.securitytracker.com/id?1019356
- http://www.symantec.com/avcenter/security/Content/2008.02.07.html
- http://www.vupen.com/english/advisories/2008/0474
Raw JSON (NVD)
Show
{
"id": "CVE-2008-0640",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-08T02:00:00.000",
"references": [
{
"url": "http://secunia.com/advisories/28853",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27644",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1019356",
"source": "cve@mitre.org"
},
{
"url": "http://www.symantec.com/avcenter/security/Content/2008.02.07.html",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0474",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28853",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27644",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1019356",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/avcenter/security/Content/2008.02.07.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0474",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing."
},
{
"lang": "es",
"value": "Symantec Ghost Solution Suite versión 1.1 anterior a 1.1 parche 2, versiones 2.0.0 y 2.0.1 no autentica las conexiones entre la consola y Ghost Management Agent, lo que permite a los atacantes remotos ejecutar comandos arbitrarios por medio de peticiones RPC no especificadas en conjunto con suplantación de ARP."
}
],
"lastModified": "2026-06-16T22:50:02.620",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:ghost_solutions_suite:1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A66AA7A-B410-45E8-8BB0-1F349BB30422"
},
{
"criteria": "cpe:2.3:a:symantec:ghost_solutions_suite:2.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27FA37CC-D408-4213-8A3F-C46C97008E33"
},
{
"criteria": "cpe:2.3:a:symantec:ghost_solutions_suite:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFEA8748-EE69-4803-96B1-9359F45022C7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}