CVE-2013-1659Out-of-bounds Write in Vmware Esxi

4 documents4 sources
Severity
7.6HIGHNVD
EPSS
0.9%
top 24.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 17

Description

VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.

CVSS vector

AV:N/AC:H/C:C/I:C/A:CExploitability: 4.9 | Impact: 10.0

Affected Packages3 packages

NVDvmware/vcenter_server4.0, 5.0+1
NVDvmware/esxi5 versions+4
NVDvmware/vcenter5.1, 5.1.0a+1

🔴Vulnerability Details

2
GHSA
GHSA-6232-r5r4-983j: VMware vCenter Server 42022-05-17
CVEList
CVE-2013-1659: VMware vCenter Server 42013-02-22

💥Exploits & PoCs

1
Exploit-DB
Good for Enterprise 2.2.2.1611 - Cross-Site Scripting2013-09-25
CVE-2013-1659 — Out-of-bounds Write in Vmware Esxi | cvebase