← Back to CVE List
Vulnerability Intelligence Report

CVE-2009-2856

Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.

No Active Exploit Signals
CVSS Base Score
3.5
LOW
EPSS Probability:1.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
sun virtual_desktop_infrastructure 3.0
sun solaris 10.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.320%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2009-08-18T00:00:00
Published2009-08-18T22:00:00
Last Updated2024-09-16T22:51:15

LINK COPIED TO CLIPBOARD