CVE-2009-3923
The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.35% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- sun/virtual desktop infrastructure · sun/virtualbox
- Source
- cve@mitre.org
References
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-268328-1
- http://www.securityfocus.com/bid/36917Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54136
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-268328-1
- http://www.securityfocus.com/bid/36917Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54136
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.