// For flags

CVE-2008-4389

 

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors.

Symantec AppStream v5.2.x y Symantec Workspace Streaming (SWS) v6.1.x antes de v6.1 SP4 no realiza la autenticación correctamente, lo que permite descargar, a servidores de streaming remotos y a atacantes "man-in-the-middle", archivos ejecutables de su elección en un sistema cliente y ejecutar estos archivos, a través de vectores no especificados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-10-02 CVE Reserved
  • 2010-06-17 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Symantec
Search vendor "Symantec"
Workspace Streaming
Search vendor "Symantec" for product "Workspace Streaming"
6.1
Search vendor "Symantec" for product "Workspace Streaming" and version "6.1"
-
Affected
Symantec
Search vendor "Symantec"
Workspace Streaming
Search vendor "Symantec" for product "Workspace Streaming"
6.1
Search vendor "Symantec" for product "Workspace Streaming" and version "6.1"
sp1
Affected
Symantec
Search vendor "Symantec"
Workspace Streaming
Search vendor "Symantec" for product "Workspace Streaming"
6.1
Search vendor "Symantec" for product "Workspace Streaming" and version "6.1"
sp2
Affected
Symantec
Search vendor "Symantec"
Workspace Streaming
Search vendor "Symantec" for product "Workspace Streaming"
6.1
Search vendor "Symantec" for product "Workspace Streaming" and version "6.1"
sp3
Affected
Symantec
Search vendor "Symantec"
Appstream
Search vendor "Symantec" for product "Appstream"
5.2
Search vendor "Symantec" for product "Appstream" and version "5.2"
-
Affected
Symantec
Search vendor "Symantec"
Appstream
Search vendor "Symantec" for product "Appstream"
5.2.1
Search vendor "Symantec" for product "Appstream" and version "5.2.1"
-
Affected
Symantec
Search vendor "Symantec"
Appstream
Search vendor "Symantec" for product "Appstream"
5.2.2
Search vendor "Symantec" for product "Appstream" and version "5.2.2"
-
Affected
Symantec
Search vendor "Symantec"
Appstream
Search vendor "Symantec" for product "Appstream"
5.2.3
Search vendor "Symantec" for product "Appstream" and version "5.2.3"
-
Affected