PT-2014-8497 · Vmware · Vmware Vcloud Automation Center+1
Published
2014-12-11
·
Updated
2018-10-09
·
CVE-2014-8373
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware vCloud Automation Center versions 6.0.1 through 6.1.1
Description
The issue allows remote authenticated users to gain privileges via vectors involving the "Connect (by) Using VMRC" function in the VMware Remote Console (VMRC) function.
Recommendations
For versions 6.0.1 through 6.1.1, consider restricting access to the VMRC function until a fix is available. As a temporary workaround, limit the use of the "Connect (by) Using VMRC" function to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Remote Console
Vmware Vcloud Automation Center