« Volver al listado

CVE-2008-4389

Estado: ModificadaAlta (9.3)—

Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-4389",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-06-17T16:30:01.293",
  "references": [
    {
      "url": "http://secunia.com/advisories/40233",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/221257",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/40611",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100616_00",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1511",
      "source": "cret@cert.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/59504",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/40233",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/221257",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/40611",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100616_00",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1511",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/59504",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Symantec AppStream v5.2.x y Symantec Workspace Streaming (SWS) v6.1.x antes de v6.1 SP4 no realiza la autenticación correctamente, lo que permite descargar, a servidores de streaming remotos y a atacantes \"man-in-the-middle\", archivos ejecutables de su elección en un sistema cliente y ejecutar estos archivos, a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T22:57:43.327",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96313018-84AD-4DB4-B5FE-23A49840C0C7"
            },
            {
              "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "376E49E5-5631-4CFE-AF04-ABE615F3F2FA"
            },
            {
              "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25254E74-3A33-4FAA-914C-1BEE7388F478"
            },
            {
              "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C14E8F23-7CCA-4371-922A-7994E1D37879"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:appstream:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CC38EC4-C066-44E8-8212-EA2151824915"
            },
            {
              "criteria": "cpe:2.3:a:symantec:appstream:5.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "832A2E1A-4EFB-4DAD-959D-4DF35E5275CF"
            },
            {
              "criteria": "cpe:2.3:a:symantec:appstream:5.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60C52587-6CD3-48CB-8438-660185B97565"
            },
            {
              "criteria": "cpe:2.3:a:symantec:appstream:5.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F29D4BC-CDC9-443A-8414-B92FFE8159D8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}