CVE-2015-1047
published 2015-10-12CVE-2015-1047: vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.32%
87.2th percentile
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter and ESXi updates address critical security issues.
vendor_vmware·2015-10-01·CVSS 7.5
CVE-2015-1047 [HIGH] VMware vCenter and ESXi updates address critical security issues.
VMSA-2015-0007: VMware vCenter and ESXi updates address critical security issues.
a. VMware ESXi OpenSLP Remote Code Execution VMware ESXi contains a double free flaw in OpenSLP's SLPDProcessMessage() function. Exploitation of this issue may allow an unauthenticated attacker to remotely execute code on the ESXi host. VMware would like to thank Qinghao Tang of QIHU 360 for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2015-5177 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ===== Product Version ===== Running on ====== Replace with/ Apply Patch ================== VMware Product =====ESXi Product V
GHSA
GHSA-296x-83m2-v73h: vpxd in VMware vCenter Server 5
ghsa_unreviewed·2022-05-14
CVE-2015-1047 [MEDIUM] CWE-20 GHSA-296x-83m2-v73h: vpxd in VMware vCenter Server 5
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
No detection rules found.
2015-10-12
Published