CVE-2013-1405

Severity
10.0CRITICAL
EPSS
0.9%
top 24.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 17

Description

VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages6 packages

NVDvmware/vsphere_client4.0, 4.1+1
NVDvmware/vcenter_server4.0, 4.1+1
NVDvmware/esxi3.5, 4.0, 4.1+2

🔴Vulnerability Details

2
GHSA
GHSA-v887-6g7g-j8hv: VMware vCenter Server 42022-05-17
CVEList
CVE-2013-1405: VMware vCenter Server 42013-02-15
CVE-2013-1405 (CRITICAL CVSS 10) | VMware vCenter Server 4.0 before Up | cvebase.io