CVE-2006-5990
published 2006-11-21CVE-2006-5990: VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is…
PriorityP414medium4CVSS 2.0
AVNACHAuNCNIPAP
EPSS
0.89%
55.0th percentile
VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 certificate when creating an SSL session, which allows remote malicious servers to spoof valid servers via a man-in-the-middle attack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | virtualcenter | — | — |
| vmware | virtualcenter | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMWare VirtualCenter 1.4.1/2.0.1 input validation (XFDB-30477 / BID-21231)
vuldb·2026-04-28·CVSS 4.0
CVE-2006-5990 [MEDIUM] VMWare VirtualCenter 1.4.1/2.0.1 input validation (XFDB-30477 / BID-21231)
A vulnerability marked as critical has been reported in VMWare VirtualCenter 1.4.1/2.0.1. This issue affects some unknown processing. Performing a manipulation results in improper input validation.
This vulnerability is known as CVE-2006-5990. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-jr99-r38w-q3wj: VMWare VirtualCenter client 2
ghsa_unreviewed·2022-05-01
CVE-2006-5990 [MEDIUM] CWE-20 GHSA-jr99-r38w-q3wj: VMWare VirtualCenter client 2
VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 certificate when creating an SSL session, which allows remote malicious servers to spoof valid servers via a man-in-the-middle attack.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://kb.vmware.com/kb/4646606http://secunia.com/advisories/23053http://securitytracker.com/id?1017270http://www.securityfocus.com/archive/1/452275/100/0/threadedhttp://www.securityfocus.com/bid/21231http://www.vmware.com/download/vi/vc-201-200611-patch.htmlhttp://www.vupen.com/english/advisories/2006/4655https://exchange.xforce.ibmcloud.com/vulnerabilities/30477http://kb.vmware.com/kb/4646606http://secunia.com/advisories/23053http://securitytracker.com/id?1017270http://www.securityfocus.com/archive/1/452275/100/0/threadedhttp://www.securityfocus.com/bid/21231http://www.vmware.com/download/vi/vc-201-200611-patch.htmlhttp://www.vupen.com/english/advisories/2006/4655https://exchange.xforce.ibmcloud.com/vulnerabilities/30477
2006-11-21
Published