CVE-2014-1210
published 2014-04-11CVE-2014-1210: VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to…
PriorityP422medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
0.68%
48.2th percentile
VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vsphere_client | — | — |
| vmware | vsphere_client | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vSphere Client updates address security vulnerabilities
vendor_vmware·2014-04-10·CVSS 9.3
CVE-2014-1209 [CRITICAL] VMware vSphere Client updates address security vulnerabilities
VMSA-2014-0003: VMware vSphere Client updates address security vulnerabilities
a. vSphere Client Insecure Client Download vSphere Client contains a vulnerability in accepting an updated vSphere Client file from an untrusted source. The vulnerability may allow a host to direct vSphere Client to download and execute an arbitrary file from any URI. This issue can be exploited if the host has been compromised or if a user has been tricked into clicking a malicious link. VMware would like to thank Recurity Labs GmbH and the Bundesamt Sicherheit in der Informationstechnik (BSI) for reporting this issue to us The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-1209 to this issue. Column 4 of the following table lists the action required to remediate th
GHSA
GHSA-7rj8-xh5v-9hqg: VMware vSphere Client 5
ghsa_unreviewed·2022-05-17
CVE-2014-1210 [MEDIUM] GHSA-7rj8-xh5v-9hqg: VMware vSphere Client 5
VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-04-11
Published