CVE-2015-6932

VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
vmwarevcenter_server
5.5
vmwarevcenter_server
5.5:1
vmwarevcenter_server
5.5:1a
vmwarevcenter_server
5.5:1b
vmwarevcenter_server
5.5:1c
vmwarevcenter_server
5.5:2
vmwarevcenter_server
5.5:2b
vmwarevcenter_server
5.5:2d
vmwarevcenter_server
5.5:2e
vmwarevcenter_server
6.0
vmwarevcenter_server
6.0:a
vmwarevcenter_server
6.0:b
𝑥
= Vulnerable software versions
Common Weakness Enumeration