Vulnerability Name: | CVE-2008-1392 (CCN-41551) | ||||||||
Assigned: | 2008-03-17 | ||||||||
Published: | 2008-03-17 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-16 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-1392 Source: MLIST Type: UNKNOWN [security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues Source: GENTOO Type: UNKNOWN GLSA-201209-25 Source: SREASON Type: UNKNOWN 3755 Source: CCN Type: OSVDB ID: 43896 VMware Multiple Products Anonymous VIX API Call Guest OS Console Access Source: BUGTRAQ Type: UNKNOWN 20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues Source: BID Type: UNKNOWN 28276 Source: CCN Type: BID-28276 VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities Source: CCN Type: VMSA-2008-0005 Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line. Source: CONFIRM Type: Patch, Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2008-0005.html Source: CONFIRM Type: Patch, Vendor Advisory http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html Source: CONFIRM Type: Patch, Vendor Advisory http://www.vmware.com/support/player2/doc/releasenotes_player2.html Source: CONFIRM Type: UNKNOWN http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html Source: XF Type: UNKNOWN vmware-vix-api-unspecified(41551) Source: XF Type: UNKNOWN vmware-vix-api-unspecified(41551) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |