First published: Fri Feb 08 2008(Updated: )
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Ghost Solution Suite | =2.0.1 | |
Symantec Ghost Solution Suite | =2.0.0 | |
Symantec Ghost Solution Suite | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0640 is considered a high severity vulnerability due to its potential for remote command execution.
To fix CVE-2008-0640, upgrade to Symantec Ghost Solution Suite version 1.1 patch 2 or later, or to version 2.0.0 or 2.0.1.
CVE-2008-0640 enables remote attackers to execute arbitrary commands through unspecified RPC requests.
CVE-2008-0640 affects Symantec Ghost Solution Suite versions 1.1 before patch 2, 2.0.0, and 2.0.1.
The cause of CVE-2008-0640 is the lack of authentication for connections between the console and the Ghost Management Agent.