← Back

CVE-2014-8371

nvd nist
Published: Dec 8, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.

Affected (9)

1 product
Vcenter Server Appliance
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 5.0 update_1
Version 5.0 update_2
Version 5.0 update_3
Version 5.0 update_3a
Version 5.1
Version 5.1 update_1
Version 5.1 update_2
Version 5.5
Version 5.5 update_1

Related CWEs

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.