CVE-2008-4278

VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:vmware:virtual_infrastructure_client:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:*:update_2:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:2.0:unknown:client:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:2.0.2:update_2:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:2.0.2:update_3:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:2.0.2:update_4:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:2.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:virtualcenter:2.5:update_1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-10-06 19:54

Updated : 2023-12-10 10:51


NVD link : CVE-2008-4278

Mitre link : CVE-2008-4278

CVE.ORG link : CVE-2008-4278


JSON object : View

Products Affected

microsoft

  • windows

vmware

  • virtual_infrastructure_client
  • virtualcenter
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor