CVE-2017-4940

The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when other users access the Host Client.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vmwareCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
vmwareesxi
5.5
vmwareesxi
5.5:1
vmwareesxi
5.5:2
vmwareesxi
5.5:3a
vmwareesxi
5.5:3b
vmwareesxi
5.5:550-20170901001s
vmwareesxi
6.0
vmwareesxi
6.0:1
vmwareesxi
6.0:1a
vmwareesxi
6.0:1b
vmwareesxi
6.0:2
vmwareesxi
6.0:3
vmwareesxi
6.0:3a
vmwareesxi
6.0:600-201504401
vmwareesxi
6.0:600-201505401
vmwareesxi
6.0:600-201507101
vmwareesxi
6.0:600-201507102
vmwareesxi
6.0:600-201507401
vmwareesxi
6.0:600-201507402
vmwareesxi
6.0:600-201507403
vmwareesxi
6.0:600-201507404
vmwareesxi
6.0:600-201507405
vmwareesxi
6.0:600-201507406
vmwareesxi
6.0:600-201507407
vmwareesxi
6.0:600-201509101
vmwareesxi
6.0:600-201509102
vmwareesxi
6.0:600-201509201
vmwareesxi
6.0:600-201509202
vmwareesxi
6.0:600-201509203
vmwareesxi
6.0:600-201509204
vmwareesxi
6.0:600-201509205
vmwareesxi
6.0:600-201509206
vmwareesxi
6.0:600-201509207
vmwareesxi
6.0:600-201509208
vmwareesxi
6.0:600-201509209
vmwareesxi
6.0:600-201509210
vmwareesxi
6.0:600-201510401
vmwareesxi
6.0:600-201511401
vmwareesxi
6.0:600-201601101
vmwareesxi
6.0:600-201601102
vmwareesxi
6.0:600-201601401
vmwareesxi
6.0:600-201601402
vmwareesxi
6.0:600-201601403
vmwareesxi
6.0:600-201601404
vmwareesxi
6.0:600-201601405
vmwareesxi
6.0:600-201602401
vmwareesxi
6.0:600-201603101
vmwareesxi
6.0:600-201603102
vmwareesxi
6.0:600-201603201
vmwareesxi
6.0:600-201603202
vmwareesxi
6.0:600-201603203
vmwareesxi
6.0:600-201603204
vmwareesxi
6.0:600-201603205
vmwareesxi
6.0:600-201603206
vmwareesxi
6.0:600-201603207
vmwareesxi
6.0:600-201603208
vmwareesxi
6.0:600-201605401
vmwareesxi
6.0:600-201608101
vmwareesxi
6.0:600-201608401
vmwareesxi
6.0:600-201608402
vmwareesxi
6.0:600-201608403
vmwareesxi
6.0:600-201608404
vmwareesxi
6.0:600-201608405
vmwareesxi
6.0:600-201610410
vmwareesxi
6.0:600-201611401
vmwareesxi
6.0:600-201611402
vmwareesxi
6.0:600-201611403
vmwareesxi
6.0:600-201702101
vmwareesxi
6.0:600-201702102
vmwareesxi
6.0:600-201702201
vmwareesxi
6.0:600-201702202
vmwareesxi
6.0:600-201702203
vmwareesxi
6.0:600-201702204
vmwareesxi
6.0:600-201702205
vmwareesxi
6.0:600-201702206
vmwareesxi
6.0:600-201702207
vmwareesxi
6.0:600-201702208
vmwareesxi
6.0:600-201702209
vmwareesxi
6.0:600-201702210
vmwareesxi
6.0:600-201702211
vmwareesxi
6.0:600-201702212
vmwareesxi
6.0:600-201703401
vmwareesxi
6.0:600-201706101
vmwareesxi
6.0:600-201706102
vmwareesxi
6.0:600-201706103
vmwareesxi
6.0:600-201706401
vmwareesxi
6.0:600-201706402
vmwareesxi
6.0:600-201706403
vmwareesxi
6.0:600-201710301
vmwareesxi
6.5
vmwareesxi
6.5:650-201701001
vmwareesxi
6.5:650-201703001
vmwareesxi
6.5:650-201703002
vmwareesxi
6.5:650-201704001
vmwareesxi
6.5:650-201707101
vmwareesxi
6.5:650-201707102
vmwareesxi
6.5:650-201707103
vmwareesxi
6.5:650-201707201
vmwareesxi
6.5:650-201707202
vmwareesxi
6.5:650-201707203
vmwareesxi
6.5:650-201707204
vmwareesxi
6.5:650-201707205
vmwareesxi
6.5:650-201707206
vmwareesxi
6.5:650-201707207
vmwareesxi
6.5:650-201707208
vmwareesxi
6.5:650-201707209
vmwareesxi
6.5:650-201707210
vmwareesxi
6.5:650-201707211
vmwareesxi
6.5:650-201707212
vmwareesxi
6.5:650-201707213
vmwareesxi
6.5:650-201707214
vmwareesxi
6.5:650-201707215
vmwareesxi
6.5:650-201707216
vmwareesxi
6.5:650-201707217
vmwareesxi
6.5:650-201707218
vmwareesxi
6.5:650-201707219
vmwareesxi
6.5:650-201707220
vmwareesxi
6.5:650-201707221
vmwareesxi
6.5:650-201710001
vmwareesxi
6.5:650-201712001
𝑥
= Vulnerable software versions