PT-2020-3058 · Vmware · Vmware Esxi

Published

2020-04-29

·

Updated

2020-05-08

·

CVE-2020-3955

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions VMware ESXi versions 6.5 through 6.5 without patch ESXi650-201912104-SG VMware ESXi versions 6.7 through 6.7 without patch ESXi670-202004103-SG
Description The issue is related to the failure to protect the structure of web pages, which can be exploited by a remote attacker to perform a cross-site scripting attack.
Recommendations For ESXi 6.5, apply patch ESXi650-201912104-SG to resolve the issue. For ESXi 6.7, apply patch ESXi670-202004103-SG to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03349
CVE-2020-3955

Affected Products

Vmware Esxi