CVE-2014-8371
08.12.2014, 11:59
VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | vcenter_server_appliance | 5.0:update_1 |
vmware | vcenter_server_appliance | 5.0:update_2 |
vmware | vcenter_server_appliance | 5.0:update_3 |
vmware | vcenter_server_appliance | 5.0:update_3a |
vmware | vcenter_server_appliance | 5.1 |
vmware | vcenter_server_appliance | 5.1:update_1 |
vmware | vcenter_server_appliance | 5.1:update_2 |
vmware | vcenter_server_appliance | 5.5 |
vmware | vcenter_server_appliance | 5.5:update_1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References