PT-2015-7411 · Vmware · Vmware Vcenter Server+1

Published

2015-09-18

·

Updated

2020-07-13

·

CVE-2015-6932

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions VMware vCenter Server versions 5.5 before u3 and 6.0 before u1
Description The issue allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted X.509 certificate, as the software does not verify X.509 certificates from TLS LDAP servers.
Recommendations For versions 5.5 before u3, update to version 5.5 u3 or later. For versions 6.0 before u1, update to version 6.0 u1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6932

Affected Products

Vmware Vcenter
Vmware Vcenter Server