CVE-2008-5417 describes a local privilege escalation vulnerability in HP DECnet-Plus 8.3 (before ECO03) for OpenVMS on Alpha platforms. The vulnerability stems from world-writable permissions on the OSIT$NAMES logical name table, allowing local users to bypass access controls and modify the table using SYS$CRELNM and SYS$DELLNM system services. With a CVSS score of 2.1 (low severity) and a FAUCET Risk Score of 5/100, the impact is limited to integrity compromise (I:P) with no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low threat profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3CPE matchmatch criteria | cpe:2.3:a:hp:decnet_plus_for_openvms:8.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.