Vulnerability Description
Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Workspace Streaming | 6.1 |
| Symantec | Appstream | 5.2 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/40233
- http://www.kb.cert.org/vuls/id/221257US Government Resource
- http://www.securityfocus.com/bid/40611
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=securit
- http://www.vupen.com/english/advisories/2010/1511
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59504
- http://secunia.com/advisories/40233
- http://www.kb.cert.org/vuls/id/221257US Government Resource
- http://www.securityfocus.com/bid/40611
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=securit
- http://www.vupen.com/english/advisories/2010/1511
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59504
FAQ
What is CVE-2008-4389?
CVE-2008-4389 is a vulnerability with a CVSS score of 9.3 (HIGH). Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attac...
How severe is CVE-2008-4389?
CVE-2008-4389 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4389?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Workspace Streaming, Symantec Appstream.