CVE-2014-3796
published 2014-09-15CVE-2014-3796: VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, which allows…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.58%
72.6th percentile
VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, which allows attackers to obtain sensitive information via unspecified vectors.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | nsx | — | — |
| vmware | nsx | — | — |
| vmware | nsx | — | — |
| vmware | nsx | — | — |
| vmware | nsx | — | — |
| vmware | nsx | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vcloud_networking_and_security | — | — |
| vmware | vmware_nsx | — | — |
| vmware | vsphere | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware NSX and vCNS product updates address a critical information disclosure vulnerability.
vendor_vmware·2014-09-11·CVSS 5.0
CVE-2014-3796 [MEDIUM] VMware NSX and vCNS product updates address a critical information disclosure vulnerability.
VMSA-2014-0009: VMware NSX and vCNS product updates address a critical information disclosure vulnerability.
a. VMware NSX and vCNS information disclosure vulnerability VMware NSX and vCNS contain an input validation vulnerability. This issue may allow for critical information disclosure. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2014-3796 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product NSX Edge Product Version 6.1 Running on any Replace with/ Apply Patch not affected VMware Product NSX Edge Product Version 6.0 Running on any Replace with/ Apply Patch 6.
GHSA
GHSA-vj9r-p3wm-qv47: VMware NSX 6
ghsa_unreviewed·2022-05-17
CVE-2014-3796 [MEDIUM] CWE-20 GHSA-vj9r-p3wm-qv47: VMware NSX 6
VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, which allows attackers to obtain sensitive information via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/59938http://www.securitytracker.com/id/1030835http://www.vmware.com/security/advisories/VMSA-2014-0009.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/95926http://secunia.com/advisories/59938http://www.securitytracker.com/id/1030835http://www.vmware.com/security/advisories/VMSA-2014-0009.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/95926
2014-09-15
Published