PT-2010-5540 · Vmware · Vmware Esxi

Published

2010-12-22

·

Updated

2018-10-10

·

CVE-2010-4573

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware ESXi version 4.1
Description The issue concerns the Update Installer in VMware ESXi, which fails to properly configure the SFCB authentication mode when a modified sfcb.cfg is present. This allows remote attackers to gain access using any username and password.
Recommendations For VMware ESXi version 4.1, ensure proper configuration of the SFCB authentication mode to prevent unauthorized access. As a temporary workaround, consider restricting access to the SFCB service until a proper configuration can be applied.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4573

Affected Products

Vmware Esxi