CVE-2009-0518

Severity
2.1LOW
EPSS
0.1%
top 82.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6
Latest updateMay 2

Description

VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-28gr-8m4j-v4j7: VI Client in VMware VirtualCenter before 22022-05-02
CVEList
CVE-2009-0518: VI Client in VMware VirtualCenter before 22009-04-06

💥Exploits & PoCs

1
Exploit-DB
Smart PHP Subscriber - Multiple Disclosure Vulnerabilities2009-12-14