PT-2013-3130 · Vmware · Vmware Esxi+5
Published
2013-02-15
·
Updated
2013-02-15
·
CVE-2013-1405
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware vCenter Server versions 4.0 through 4.1 before Update 3a
VMware VirtualCenter version 2.5
VMware vSphere Client versions 4.0 through 4.1 before Update 3a
VMware VI-Client version 2.5
VMware ESXi versions 3.5 through 4.1
VMware ESX versions 3.5 through 4.1
Description
The issue is related to the improper implementation of the management authentication protocol in the affected software. This allows remote servers to execute arbitrary code or cause a denial of service due to memory corruption via unspecified vectors.
Recommendations
For VMware vCenter Server versions 4.0 through 4.1 before Update 3a, update to a version that includes Update 3a or later.
For VMware VirtualCenter version 2.5, consider upgrading to a newer version of vCenter Server.
For VMware vSphere Client versions 4.0 through 4.1 before Update 3a, update to a version that includes Update 3a or later.
For VMware VI-Client version 2.5, consider upgrading to a newer version of vSphere Client.
For VMware ESXi versions 3.5 through 4.1, update to a version later than 4.1.
For VMware ESX versions 3.5 through 4.1, update to a version later than 4.1.
Fix
DoS
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Vcenter
Vmware Esxi
Vmware Vi-Client
Vmware Virtualcenter
Vmware Vcenter Server
Vmware Vsphere Client