Vulnerability Description
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Hp-Ux | 11.11 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/26873Vendor Advisory
- http://www.securityfocus.com/bid/25740
- http://www.securitytracker.com/id?1018709
- http://www.vupen.com/english/advisories/2007/3230Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36702
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c01167886
- http://secunia.com/advisories/26873Vendor Advisory
- http://www.securityfocus.com/bid/25740
- http://www.securitytracker.com/id?1018709
- http://www.vupen.com/english/advisories/2007/3230Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36702
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c01167886
FAQ
What is CVE-2007-5008?
CVE-2007-5008 is a vulnerability with a CVSS score of 9.0 (HIGH). The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
How severe is CVE-2007-5008?
CVE-2007-5008 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5008?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Hp-Ux.