CVE-2008-4315
published 2008-11-27CVE-2008-4315: tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.70%
84.2th percentile
tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tog-pegasus: failed authentication attempts not logged via PAM
vendor_redhat·2008-08-14·CVSS 6.8
CVE-2008-4315 [MEDIUM] tog-pegasus: failed authentication attempts not logged via PAM
tog-pegasus: failed authentication attempts not logged via PAM
tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.
GHSA
GHSA-xwjw-7gc4-5h47: tog-pegasus in OpenGroup Pegasus 2
ghsa_unreviewed·2022-05-02
CVE-2008-4315 [MEDIUM] GHSA-xwjw-7gc4-5h47: tog-pegasus in OpenGroup Pegasus 2
tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4315 tog-pegasus: failed authentication attempts not logged via PAM
bugzilla·2008-11-18·CVSS 6.8
CVE-2008-4315 [MEDIUM] CVE-2008-4315 tog-pegasus: failed authentication attempts not logged via PAM
CVE-2008-4315 tog-pegasus: failed authentication attempts not logged via PAM
A security flaw was found in the OpenPegasus WBEM service, shipped as
tog-pegasus package within the Red Hat Enterprise Linux. It was discovered,
the OpenPegasus service did not log failed authentication attempts to
the system log file via the traditional Pluggable Authentication Modules
mechanism. An attacker could use this flaw to discover the password
of the root account used for the authentication against the CIM server.
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-1001.html
Fedora:
https://admin.fedoraproject.org/updates/F10/FEDORA-2008-10061
https://admin.fedoraproject.org/updates/F9/FEDORA-2008-9688
arXiv
A Review on C3I Systems' Security: Vulnerabilities, Attacks, and Countermeasures
arxiv_fulltext·2022-01-31
A Review on C3I Systems' Security: Vulnerabilities, Attacks, and Countermeasures
A Review on C3I Systems' Security: Vulnerabilities, Attacks, and Countermeasures
Hussain Ahmad
[email protected]
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide, CSCRC - Cyber Security Cooperative Research Centre
Australia
Isuru Dharmadasa
[email protected]
Faheem Ullah
[email protected]
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Australia
M. Ali Babar
[email protected]
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide, CSCRC - Cyber Security Cooperative Research Centre
Australia
Authors' addresses: Hussain Ahmad, [email protected]; Isuru Dharmadasa, isuru.mahaganiarach
http://osvdb.org/50278http://secunia.com/advisories/32862http://www.redhat.com/support/errata/RHSA-2008-1001.htmlhttp://www.securitytracker.com/id?1021281https://admin.fedoraproject.org/updates/tog-pegasus-2.7.0-7.fc9https://admin.fedoraproject.org/updates/tog-pegasus-2.7.1-3.fc10https://bugzilla.redhat.com/show_bug.cgi?id=472017https://exchange.xforce.ibmcloud.com/vulnerabilities/46830https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9431http://osvdb.org/50278http://secunia.com/advisories/32862http://www.redhat.com/support/errata/RHSA-2008-1001.htmlhttp://www.securitytracker.com/id?1021281https://admin.fedoraproject.org/updates/tog-pegasus-2.7.0-7.fc9https://admin.fedoraproject.org/updates/tog-pegasus-2.7.1-3.fc10https://bugzilla.redhat.com/show_bug.cgi?id=472017https://exchange.xforce.ibmcloud.com/vulnerabilities/46830https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9431
2008-11-27
Published