CVE-2013-1405
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD
Description
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Affected (20)
Products: Vmware: Vcenter Server, Virtualcenter, Vsphere Client, Vi Client, Esxi, Esx
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 update_4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.5 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 update_4 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.