Search/CVE-2008-2139
CVE

CVE-2008-2139

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.

CVSS v3.1
EPSS
0.36%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
2 relationships
Timeline
disclosure → media coverage
May 12, 2008
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026