SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-2139

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain…

MEDIUM 6.5EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.

CVSS 2.0
6.5 MEDIUMAV:A/AC:H/Au:S/C:C/I:C/A:C
EPSS
0.36% probability · 30th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
rpath/appliance platform agent
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.