5.3

CVE-2023-34037

VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Horizon Client Version 2006
VMware ≫ Horizon Client Version 2012
VMware ≫ Horizon Client Version 2103
VMware ≫ Horizon Client Version 2106
VMware ≫ Horizon Client Version 2111
VMware ≫ Horizon Client Version 2111.1
VMware ≫ Horizon Client Version 2203
VMware ≫ Horizon Client Version 2212
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.379
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
VMware 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

https://www.vmware.com/security/advisories/VMSA-2023-0017.html
Vendor Advisory