← Back

CVE-2017-4952

nvd nist
Published: May 2, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of this issue may result in information disclosure.

Affected (15)

Products: Vmware: Xenon
1 product
Xenon
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 1.0.0 to 1.5.3
Version 1.1.0 cr0-3
Version 1.1.0 cr3_1
Version 1.3.7 cr1_2
Version 1.4.2 cr4_1
Version 1.5.4 cr2
Version 1.5.4 cr3
Version 1.5.4 cr4
Version 1.5.4 cr5
Version 1.5.4 cr6
Version 1.5.4 cr6_1
Version 1.5.4 cr6_2
Version 1.5.4 cr7
Version 1.5.4_8
Version 1.5.7_7

References (22)

Source: security@vmware.com
Mailing ListThird Party Advisory
Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.