Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-4722


Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.


Security Impact Summary

CVE-2008-4722 is a security vulnerability that . Impacting 37 products from sun, from sun, from sun and 34 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Originally identified in 2008, this vulnerability predates many modern security frameworks and practices. The vulnerability landscape of that era was characterized by different threat models and less mature defense mechanisms compared to contemporary standards.


Published

2008-10-23T22:00:01.527

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-287
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sun integrated_lights-out_manager * Yes
Hardware sun blade_6000_modular_system_with_chassis ≤ 2.0 Yes
Hardware sun blade_6048_modular_system_with_chassis ≤ 2.0 Yes
Hardware sun blade_8000_modular_system ≤ 2.1.1 Yes
Hardware sun blade_8000p_modular_system ≤ 2.1.1 Yes
Hardware sun blade_t6320_server_module ≤ 7.1.6 Yes
Hardware sun blade_x6220_with_server_module_software ≤ 2.0 Yes
Hardware sun blade_x6250_with_server_module_software ≤ 2.0 Yes
Hardware sun blade_x6450_with_server_module_software ≤ 2.0 Yes
Hardware sun blade_x8400 ≤ 2.0.2 Yes
Hardware sun blade_x8420 ≤ 2.0.2 Yes
Hardware sun blade_x8440 ≤ 2.0.2 Yes
Hardware sun blade_x8450 ≤ 2.1 Yes
Hardware sun fire_x2250_server ≤ sw_1.1 Yes
Hardware sun fire_x4100_server ≤ sw_1.5.1 Yes
Hardware sun fire_x4100m2_server ≤ sw_2.1 Yes
Hardware sun fire_x4140_server ≤ sw_2.1 Yes
Hardware sun fire_x4150_server ≤ sw_2.0 Yes
Hardware sun fire_x4200_server ≤ sw_1.5.1 Yes
Hardware sun fire_x4200m2_server ≤ sw_2.1 Yes
Hardware sun fire_x4240_server ≤ sw_2.1 Yes
Hardware sun fire_x4250_server ≤ sw_1.1 Yes
Hardware sun fire_x4440_server ≤ sw_2.1 Yes
Hardware sun fire_x4450_server ≤ sw_2.1.0 Yes
Hardware sun fire_x4500_server ≤ sw_1.5 Yes
Hardware sun fire_x4540_server ≤ sw_1.0 Yes
Hardware sun fire_x4600_server ≤ sw_1.4 Yes
Hardware sun fire_x4600m2_server ≤ sw_2.1.2 Yes
Hardware sun netra ≤ cp3260_atca_blade_server Yes
Hardware sun netra ≤ t5220_server Yes
Hardware sun netra ≤ t5440_server Yes
Hardware sun netra_x4200m2_server ≤ sw_2.1 Yes
Hardware sun netra_x4250_server ≤ sw_1.1 Yes
Hardware sun netra_x4450 ≤ sw_1.1 Yes
Hardware sun sparc_enterprise_server_t5120 ≤ 7.1.6 Yes
Hardware sun sparc_enterprise_server_t5140 ≤ 7.1.6 Yes
Hardware sun sparc_enterprise_server_t5220 ≤ 7.1.6 Yes
Hardware sun sparc_enterprise_server_t5240 ≤ 7.1.6 Yes
Hardware sun sparc_enterprise_server_t5440 ≤ 7.1.5b Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For sun's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.