Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-4190

21
FAUCET Score

CVE-2008-4190 describes a local privilege escalation vulnerability in the IPSEC livetest tool within Openswan versions 2.4.12 and earlier, and 2.6.x through 2.6.16. An attacker can exploit this flaw via a symlink attack on temporary files, leading to arbitrary file overwrites and arbitrary code execution. The CVSS score of 4.4 (AV:L/AC:M/Au:N/C:P/I:P/A:P) indicates a low-severity vulnerability requiring local access and medium attack complexity, with potential for partial confidentiality, integrity, and availability impact. While not listed on the KEV catalog or Hot List, an exploit is available on ExploitDB, though there is no evidence of active exploitation, and community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
1.0.4CPE matchmatch criteria
cpe:2.3:a:openswan:openswan:1.0.4:*:*:*:*:*:*:*
1.0.5CPE matchmatch criteria
cpe:2.3:a:openswan:openswan:1.0.5:*:*:*:*:*:*:*
1.0.6CPE matchmatch criteria
cpe:2.3:a:openswan:openswan:1.0.6:*:*:*:*:*:*:*
1.0.7CPE matchmatch criteria
cpe:2.3:a:openswan:openswan:1.0.7:*:*:*:*:*:*:*
1.0.8CPE matchmatch criteria
cpe:2.3:a:openswan:openswan:1.0.8:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.4MEDIUM

AV:L/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.11%
Probability of exploitation in next 30 days
EPSS Percentile
62.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-9135 · Jul 13, 2009
This CVE's current EPSS score of 0.0112 is in the 91st percentile among its peer group of 1,595 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

debianpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openswan-0:2.6.14-1.el5_3.2
View patch

Vendor Advisories (1)

redhatCVE-2008-4190Low

openswan: Insecure auxiliary /tmp file usage (symlink attack possible)

Aug 24, 2008

References

bugs.debian.org / cgi-bin/bugreport.cgi
Patch
dev.gentoo.org / ~rbu/security/debiantemp/openswan
bugs.gentoo.org / show_bug.cgi
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/34182
Vendor Advisory
secunia.com / advisories/34472
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/45250
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10078
exploit-db.com / exploits/9135
debian.org / security/2009/dsa-1760
Patch
openwall.com / lists/oss-security/2008/10/30/2
redhat.com / support/errata/RHSA-2009-0402.html
Patch
securityfocus.com / archive/1/501624/100/0/threaded
securityfocus.com / archive/1/501640/100/0/threaded
securityfocus.com / bid/31243
Patch