CVE-2008-4315Insufficient Logging in Redhat Enterprise Linux

Severity
6.8MEDIUMNVD
EPSS
1.6%
top 18.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27
Latest updateMay 2

Description

tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

Also affects: Enterprise Linux 5.0

🔴Vulnerability Details

1
GHSA
GHSA-xwjw-7gc4-5h47: tog-pegasus in OpenGroup Pegasus 22022-05-02

📋Vendor Advisories

1
Red Hat
tog-pegasus: failed authentication attempts not logged via PAM2008-08-14

📐Framework References

1
CWE
Insufficient Logging

📄Research Papers

1
arXiv
A Review on C3I Systems' Security: Vulnerabilities, Attacks, and Countermeasures2022-01-31

💬Community

1
Bugzilla
CVE-2008-4315 tog-pegasus: failed authentication attempts not logged via PAM2008-11-18