CVE-2008-3514
published 2008-08-13CVE-2008-3514: VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.81%
76.2th percentile
VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | virtualcenter | <= 2.0.2 | — |
| vmware | virtualcenter | — | — |
| vmware | virtualcenter | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Updated VirtualCenter addresses User Account Disclosure Vulnerability
vendor_vmware·2008-08-12·CVSS 5.0
CVE-2007-3514 [MEDIUM] Updated VirtualCenter addresses User Account Disclosure Vulnerability
VMSA-2008-0012: Updated VirtualCenter addresses User Account Disclosure Vulnerability
Updated VirtualCenter addresses User Account Disclosure Vulnerability 2. Relevant releases VirtualCenter 2.5 previous to Update 2 VirutalCenter 2.0.2 previous to Update 5 3. VirtualCenter User Account Disclosure Vulnerability An information disclosure vulnerability is present in VirtualCenter. Exploitation of this flaw might result in disclosure of the user names of system accounts. VMware would like to thank Brett Moore of Insomnia Security for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-3514 to this issue. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMw
GHSA
GHSA-2rrj-r6g7-f5gj: VMware VirtualCenter 2
ghsa_unreviewed·2022-05-02
CVE-2008-3514 [MEDIUM] CWE-200 GHSA-2rrj-r6g7-f5gj: VMware VirtualCenter 2
VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/31468http://securityreason.com/securityalert/4150http://www.insomniasec.com/advisories/ISVA-080812.1.htmhttp://www.securityfocus.com/archive/1/495386/100/0/threadedhttp://www.securityfocus.com/bid/30664http://www.securitytracker.com/id?1020693http://www.vmware.com/security/advisories/VMSA-2008-0012.htmlhttp://www.vmware.com/support/vi3/doc/releasenotes_vc202u5.htmlhttp://www.vupen.com/english/advisories/2008/2363https://exchange.xforce.ibmcloud.com/vulnerabilities/44425http://secunia.com/advisories/31468http://securityreason.com/securityalert/4150http://www.insomniasec.com/advisories/ISVA-080812.1.htmhttp://www.securityfocus.com/archive/1/495386/100/0/threadedhttp://www.securityfocus.com/bid/30664http://www.securitytracker.com/id?1020693http://www.vmware.com/security/advisories/VMSA-2008-0012.htmlhttp://www.vmware.com/support/vi3/doc/releasenotes_vc202u5.htmlhttp://www.vupen.com/english/advisories/2008/2363https://exchange.xforce.ibmcloud.com/vulnerabilities/44425
2008-08-13
Published