6.5
CVSSv2

CVE-2008-2139

Published: 12/05/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 10 | Exploitability Score: 2.5
VMScore: 578
Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C

Vulnerability Summary

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate malicious users to gain privileges and maintain control over the administrator account.

Vulnerable Product Search on Vulmon Subscribe to Product

rpath appliance platform agent 2

rpath appliance platform agent 3