cbcvebase.
CVE-2013-1405
published 2013-02-15

CVE-2013-1405: VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update…

critical10CVSS 3.1
AVNACLAuNCCICAC
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Affected

19 ranges
VendorProductVersion rangeFixed in
vmwareesx
vmwareesx
vmwareesx
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwarevcenter_server
vmwarevcenter_server
vmwarevcenter_server
vmwarevi-client
vmwarevirtualcenter
vmwarevmware_esxi
vmwarevmware_vcenter_server
vmwarevmware_vsphere
vmwarevmware_workstation
vmwarevsphere
vmwarevsphere_client
vmwarevsphere_client