SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-6440

Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.

MEDIUM 5.0EPSS 1.16%

Does this matter?

Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.

Description

Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.16% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
cerberus/cerberus helpdesk · webgroupmedia/cerberus helpdesk
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.