First published: Wed Aug 13 2008(Updated: )
VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter | =2.0.2-update_2 | |
VMware vCenter | =2.0.2-update_3 | |
VMware vCenter | =2.5-update_1 | |
VMware vCenter | =2.0.2 | |
VMware vCenter | <=2.0.2 | |
VMware vCenter | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3514 has a medium severity rating due to its potential for user credential enumeration.
To mitigate the risk of CVE-2008-3514, upgrade to VMware VirtualCenter 2.5 Update 2 or later, or 2.0.2 Update 5 or later.
CVE-2008-3514 affects VMware VirtualCenter versions 2.0.2 prior to Update 5 and 2.5 prior to Update 2.
CVE-2008-3514 is an access control vulnerability that allows attackers to infer valid user names.
Yes, by determining valid user names, CVE-2008-3514 can potentially lead to unauthorized access or further exploitation.