CVE-2017-4952

VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of this issue may result in information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vmwareCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
vmwarexenon
1.0.0 ≤
𝑥
≤ 1.5.3
vmwarexenon
1.1.0:cr0-3
vmwarexenon
1.1.0:cr3_1
vmwarexenon
1.3.7:cr1_2
vmwarexenon
1.4.2:cr4_1
vmwarexenon
1.5.4:cr2
vmwarexenon
1.5.4:cr3
vmwarexenon
1.5.4:cr4
vmwarexenon
1.5.4:cr5
vmwarexenon
1.5.4:cr6
vmwarexenon
1.5.4:cr6_1
vmwarexenon
1.5.4:cr6_2
vmwarexenon
1.5.4:cr7
vmwarexenon
1.5.4_8:_8
vmwarexenon
1.5.7_7:_7
𝑥
= Vulnerable software versions
References