Lucene search

K
cve[email protected]CVE-2013-5971
HistoryOct 21, 2013 - 10:54 a.m.

CVE-2013-5971

2013-10-2110:54:30
CWE-264
web.nvd.nist.gov
18
cve-2013-5971
session fixation
vsphere
vmware
vcenter server
web client server
remote attack
privilege escalation

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.7%

Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.

Affected configurations

NVD
Node
vmwarevcenter_serverRange5.0update_2_rc
OR
vmwarevcenter_serverMatch4.0.0.10021
OR
vmwarevcenter_serverMatch4.0.0.12305
OR
vmwarevcenter_serverMatch4.1
OR
vmwarevcenter_serverMatch4.1.0.12319
OR
vmwarevcenter_serverMatch4.1.0.14766
OR
vmwarevcenter_serverMatch4.1.0.17435
OR
vmwarevcenter_serverMatch5.0
OR
vmwarevcenter_serverMatch5.0update_1

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.7%