PT-2010-5540 · Vmware · Vmware Esxi
Published
2010-12-22
·
Updated
2018-10-10
·
CVE-2010-4573
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware ESXi version 4.1
Description
The issue concerns the Update Installer in VMware ESXi, which fails to properly configure the SFCB authentication mode when a modified sfcb.cfg is present. This allows remote attackers to gain access using any username and password.
Recommendations
For VMware ESXi version 4.1, ensure proper configuration of the SFCB authentication mode to prevent unauthorized access. As a temporary workaround, consider restricting access to the SFCB service until a proper configuration can be applied.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Esxi