OpenPegasus is a systems-management platform centered on WBEM (Web-Based Enterprise Management) implementations and management-server components that provide remote administration and monitoring across enterprise infrastructure. The durable signal in its disclosure history centers on memory-safety and input-validation weaknesses that are characteristic of native C/C++ management software operating in privileged, network-facing contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openpegasus over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0003HIGH Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_ | Jan 8, 2008 | 10.0 | 30 | NO | NO |
CVE-2011-4967HIGH tog-Pegasus has a package hash collision DoS vulnerability | Nov 19, 2019 | 7.5 | 25 | NO | NO |
CVE-2007-5360HIGH Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might all | Jan 8, 2008 | 7.5 | 25 | NO | NO |
CVE-2008-4315MEDIUM tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, whic | Nov 27, 2008 | 6.8 | 19 | NO | NO |
CVE-2008-4313MEDIUM A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access r | Nov 27, 2008 | 6.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openpegasus.
Media articles that mention a CVE ID that affects a product developed by Openpegasus — matched by CVE ID, not by vendor name.