CVE-2007-5008: Critical severity HPE HP-UX vulnerability
Published Sep 20, 2007
·Updated
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
Affected Software
3 affected components
HPE HP-UX=11.11
HPE HP-UX=11.23
HPE HP-UX=11.31
Event History
Sep 20, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5008?
CVE-2007-5008 is classified as a high severity vulnerability due to its potential to allow unauthorized privilege escalation.
2
How do I fix CVE-2007-5008?
To fix CVE-2007-5008, upgrade to the latest version of HP-UX that addresses this vulnerability.
3
What systems are affected by CVE-2007-5008?
CVE-2007-5008 affects HP-UX versions 11.11, 11.23, and 11.31.
4
What type of vulnerability is CVE-2007-5008?
CVE-2007-5008 is a privilege escalation vulnerability caused by improper reporting of password status.
5
Can CVE-2007-5008 be exploited remotely?
Yes, CVE-2007-5008 can be exploited remotely by attackers to gain unauthorized privileges.