cbcvebase.
CVE-2013-1405
published 2013-02-15

CVE-2013-1405: VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update…

PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.80%
84.9th percentile
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Affected

19 ranges
VendorProductVersion rangeFixed in
vmwareesx
vmwareesx
vmwareesx
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwarevcenter_server
vmwarevcenter_server
vmwarevcenter_server
vmwarevi-client
vmwarevirtualcenter
vmwarevmware_esxi
vmwarevmware_vcenter_server
vmwarevmware_vsphere
vmwarevmware_workstation
vmwarevsphere
vmwarevsphere_client
vmwarevsphere_client
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.