2.1

CVE-2008-4278

VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareVirtualcenter Updateupdate_2 Version <= 2.5
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
VMwareVirtualcenter Version1.4.1
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
VMwareVirtualcenter Version2.0.1
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
VMwareVirtualcenter Version2.0.2
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
VMwareVirtualcenter Version2.0.2 Updateupdate_2
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
VMwareVirtualcenter Version2.0.2 Updateupdate_3
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
VMwareVirtualcenter Version2.0.2 Updateupdate_4
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
VMwareVirtualcenter Version2.5
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
VMwareVirtualcenter Version2.5 Updateupdate_1
   VMwareVirtual Infrastructure Client
   VMwareVirtualcenter Version2.0 Updateunknown Editionclient
   MicrosoftWindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.158
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.