CVE-2008-2139
Last modified
CVE-2008-2139 is a vulnerability of currently unknown severity. The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rpath | Appliance Platform Agent | 2 |
| Rpath | Appliance Platform Agent | 3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2139?
How severe is CVE-2008-2139?
How do I fix CVE-2008-2139?
Are you affected by CVE-2008-2139?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
