Описание
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- MitigationVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:vmware:vcenter_server:5.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:6.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:6.5:*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.00915
Низкий
9 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 9
github
больше 3 лет назад
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
EPSS
Процентиль: 75%
0.00915
Низкий
9 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-306