AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-2856

LOW · CVSS 3.5 EPSS 1.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-08-18 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 3.5. It may be remotely exploitable.

CVE
CVE-2009-2856
Severity
LOW
CVSS
3.5
EPSS
1.32%

Original NVD Description

Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.