CVE-2010-4573
published 2010-12-22CVE-2010-4573: The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote…
PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.52%
83.1th percentile
The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi 4.1 Update Installer SFCB Authentication Flaw
vendor_vmware·2010-12-21·CVSS 9.3
CVE-2010-4573 [CRITICAL] VMware ESXi 4.1 Update Installer SFCB Authentication Flaw
VMSA-2010-0020: VMware ESXi 4.1 Update Installer SFCB Authentication Flaw
a. ESXi 4.1 Update Installer SFCB Authentication Flaw Under certain conditions, the ESXi 4.1 installer that upgrades an ESXi 3.5 or ESXi 4.0 host to ESXi 4.1 incorrectly handles the SFCB authentication mode. The result is that SFCB authentication could allow login with any username and password combination. An ESXi 4.1 host is affected if all of the following apply: - ESXi 4.1 was upgraded from ESXi 3.5 or ESXi 4.0. - The SFCB configuration file /etc/sfcb/sfcb.cfg was modified prior to the upgrade. - The sfcbd daemon is running (sfcbd runs by default).
CVEs: CVE-2010-4573
Affected products: VMware ESXi, VMware Tools, VMware Workstation, VMware vSphere
Red Hat
kernel: IA32 System Call Entry Point Vulnerability
vendor_redhat·2010-09-15·CVSS 7.2
CVE-2010-3301 [HIGH] CWE-681 kernel: IA32 System Call Entry Point Vulnerability
kernel: IA32 System Call Entry Point Vulnerability
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5, and Red Hat Enterprise MRG, as they do not contain the upstream commit d4d67150 that introduced this flaw.
More information can be found in this kbase: https://access.redhat.com/kb/docs/DOC-40330
GHSA
GHSA-76jq-8wqx-96ch: The Update Installer in VMware ESXi 4
ghsa_unreviewed·2022-05-14
CVE-2010-4573 [HIGH] CWE-287 GHSA-76jq-8wqx-96ch: The Update Installer in VMware ESXi 4
The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://kb.vmware.com/kb/1031761http://lists.vmware.com/pipermail/security-announce/2010/000114.htmlhttp://secunia.com/advisories/42591http://securitytracker.com/id?1024917http://www.securityfocus.com/archive/1/515420/100/0/threadedhttp://www.securityfocus.com/bid/45543http://www.vmware.com/security/advisories/VMSA-2010-0020.htmlhttp://www.vupen.com/english/advisories/2010/3303http://kb.vmware.com/kb/1031761http://lists.vmware.com/pipermail/security-announce/2010/000114.htmlhttp://secunia.com/advisories/42591http://securitytracker.com/id?1024917http://www.securityfocus.com/archive/1/515420/100/0/threadedhttp://www.securityfocus.com/bid/45543http://www.vmware.com/security/advisories/VMSA-2010-0020.htmlhttp://www.vupen.com/english/advisories/2010/3303
2010-12-22
Published