PT-2019-4333 · Vmware · Vmware Vcenter Server+2

Published

2019-09-16

·

Updated

2020-02-10

·

CVE-2019-5531

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions VMware vSphere ESXi versions 6.7 prior to ESXi670-201810101-SG VMware vSphere ESXi versions 6.5 prior to ESXi650-201811102-SG VMware vSphere ESXi versions 6.0 prior to ESXi600-201807103-SG VMware vCenter Server versions 6.7 prior to 6.7 U1b VMware vCenter Server versions 6.5 prior to 6.5 U2b VMware vCenter Server versions 6.0 prior to 6.0 U3j
Description The issue is related to insufficient session expiration, which may allow a remote attacker to gain unauthorized access to protected information. An attacker with physical access or the ability to mimic a websocket connection to a user's browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.
Recommendations For VMware vSphere ESXi version 6.7 prior to ESXi670-201810101-SG, update to ESXi670-201810101-SG or later. For VMware vSphere ESXi version 6.5 prior to ESXi650-201811102-SG, update to ESXi650-201811102-SG or later. For VMware vSphere ESXi version 6.0 prior to ESXi600-201807103-SG, update to ESXi600-201807103-SG or later. For VMware vCenter Server version 6.7 prior to 6.7 U1b, update to 6.7 U1b or later. For VMware vCenter Server version 6.5 prior to 6.5 U2b, update to 6.5 U2b or later. For VMware vCenter Server version 6.0 prior to 6.0 U3j, update to 6.0 U3j or later.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00050
CVE-2019-5531

Affected Products

Vmware Vcenter
Vmware Vcenter Server
Vmware Vsphere Esxi