SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-3514

VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then…

MEDIUM 5.0EPSS 1.81%

Does this matter?

Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.

Description

VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users."

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.81% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
vmware/virtualcenter
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.