CVE-2012-5703
published 2012-11-20CVE-2012-5703: The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1)…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.37%
82.1th percentile
The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrievePropEx SOAP request.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_vsphere | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r6hf-gvxf-pm8r: The vSphere API in VMware ESXi 4
ghsa_unreviewed·2022-05-17
CVE-2012-5703 [MEDIUM] CWE-20 GHSA-r6hf-gvxf-pm8r: The vSphere API in VMware ESXi 4
The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrievePropEx SOAP request.
VMware
VMware security updates for vSphere API and ESX Service Console
vendor_vmware·2012-11-15·CVSS 5.0
CVE-2011-4940 [MEDIUM] VMware security updates for vSphere API and ESX Service Console
VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
a. VMware vSphere API denial of service vulnerability The VMware vSphere API contains a denial of service vulnerability. This issue allows an unauthenticated user to send a maliciously crafted API request and disable the host daemon. Exploitation of the issue would prevent management activities on the host but any virtual machines running on the host would be unaffected. VMware would like to thank Sebastián Tello of Core Security Technologies for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-5703 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.coresecurity.com/content/vmware-esx-input-validation-errorhttp://www.securityfocus.com/bid/56571http://www.securitytracker.com/id?1027782http://www.vmware.com/security/advisories/VMSA-2012-0016.htmlhttp://www.coresecurity.com/content/vmware-esx-input-validation-errorhttp://www.securityfocus.com/bid/56571http://www.securitytracker.com/id?1027782http://www.vmware.com/security/advisories/VMSA-2012-0016.html
2012-11-20
Published