10

CVE-2013-1405

VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ vCenter Server Version 4.0 Update update_4
VMware ≫ vCenter Server Version 4.1 Update update_3
VMware ≫ Virtualcenter Version 2.5
VMware ≫ Vsphere Client Version 4.0 Update update_4
VMware ≫ Vsphere Client Version 4.1 Update update_3
VMware ≫ Vi-client Version 2.5
VMware ≫ ESXi Version 3.5
VMware ≫ ESXi Version 3.5 Update 1
VMware ≫ ESXi Version 4.0
VMware ≫ ESXi Version 4.0 Update 1
VMware ≫ ESXi Version 4.0 Update 2
VMware ≫ ESXi Version 4.0 Update 3
VMware ≫ ESXi Version 4.0 Update 4
VMware ≫ ESXi Version 4.1
VMware ≫ Esx Version 3.5
VMware ≫ Esx Version 3.5 Update update1
VMware ≫ Esx Version 3.5 Update update2
VMware ≫ Esx Version 3.5 Update update3
VMware ≫ Esx Version 4.0
VMware ≫ Esx Version 4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.8% 0.846
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://www.vmware.com/security/advisories/VMSA-2013-0001.html
Vendor Advisory