Lucene search

K
cveMitreCVE-2013-1405
HistoryFeb 15, 2013 - 12:09 p.m.

CVE-2013-1405

2013-02-1512:09:29
CWE-287
mitre
web.nvd.nist.gov
45
vmware
vcenter server
virtualcenter
vsphere client
vi-client
esxi
esx
vulnerability
cve-2013-1405
nvd
security
update

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.002

Percentile

64.5%

VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Affected configurations

Nvd
Node
vmwarevcenter_serverMatch4.0update_4
OR
vmwarevcenter_serverMatch4.1update_3
Node
vmwarevirtualcenterMatch2.5
Node
vmwarevsphere_clientMatch4.0update_4
OR
vmwarevsphere_clientMatch4.1update_3
Node
vmwarevi-clientMatch2.5
Node
vmwareesxiMatch3.5
OR
vmwareesxiMatch3.51
OR
vmwareesxiMatch4.0
OR
vmwareesxiMatch4.01
OR
vmwareesxiMatch4.02
OR
vmwareesxiMatch4.03
OR
vmwareesxiMatch4.04
OR
vmwareesxiMatch4.1
Node
vmwareesxMatch3.5
OR
vmwareesxMatch3.5update1
OR
vmwareesxMatch3.5update2
OR
vmwareesxMatch3.5update3
OR
vmwareesxMatch4.0
OR
vmwareesxMatch4.1
VendorProductVersionCPE
vmwarevcenter_server4.0cpe:2.3:a:vmware:vcenter_server:4.0:update_4:*:*:*:*:*:*
vmwarevcenter_server4.1cpe:2.3:a:vmware:vcenter_server:4.1:update_3:*:*:*:*:*:*
vmwarevirtualcenter2.5cpe:2.3:a:vmware:virtualcenter:2.5:*:*:*:*:*:*:*
vmwarevsphere_client4.0cpe:2.3:a:vmware:vsphere_client:4.0:update_4:*:*:*:*:*:*
vmwarevsphere_client4.1cpe:2.3:a:vmware:vsphere_client:4.1:update_3:*:*:*:*:*:*
vmwarevi-client2.5cpe:2.3:a:vmware:vi-client:2.5:*:*:*:*:*:*:*
vmwareesxi3.5cpe:2.3:o:vmware:esxi:3.5:*:*:*:*:*:*:*
vmwareesxi3.5cpe:2.3:o:vmware:esxi:3.5:1:*:*:*:*:*:*
vmwareesxi4.0cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:*
vmwareesxi4.0cpe:2.3:o:vmware:esxi:4.0:1:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.002

Percentile

64.5%