PT-2013-4139 · Vmware · Vmware Vcenter Server
Published
2013-05-01
·
Updated
2013-05-01
·
CVE-2013-3107
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
VMware vCenter Server version 5.1 before Update 1
Description
The issue allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password when anonymous LDAP binding for Active Directory is enabled.
Recommendations
For VMware vCenter Server version 5.1 before Update 1, update to Update 1 or later to resolve the issue. As a temporary workaround, consider disabling anonymous LDAP binding for Active Directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Vcenter Server