CVE-2017-4907

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vmwareCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
vmwarehorizon_view
6.0
vmwarehorizon_view
6.0.2
vmwarehorizon_view
6.1
vmwarehorizon_view
6.1.1
vmwarehorizon_view
6.2
vmwarehorizon_view
6.2.1
vmwarehorizon_view
6.2.2
vmwarehorizon_view
6.2.3
vmwarehorizon_view
6.2.4
vmwarehorizon_view
7.0
vmwareunified_access_gateway
2.5
vmwareunified_access_gateway
2.5.1
vmwareunified_access_gateway
2.7
vmwareunified_access_gateway
2.7.2
vmwareunified_access_gateway
2.8
𝑥
= Vulnerable software versions