CVE-2008-2140

Rpath Appliance Platform Agent - CSRF

Title source: rule

Description

Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.

Scores

EPSS 0.0011
EPSS Percentile 29.9%

Classification

CWE
CWE-352
Status draft

Affected Products (2)

rpath/appliance_platform_agent
rpath/appliance_platform_agent

Timeline

Published May 12, 2008
Tracked Since Feb 18, 2026