CVE-2015-6932
published 2015-09-18CVE-2015-6932: VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to…
PriorityP423medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
0.74%
50.6th percentile
VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server updates address a LDAP certificate validation issue
vendor_vmware·2015-09-16·CVSS 5.8
CVE-2015-6932 [MEDIUM] VMware vCenter Server updates address a LDAP certificate validation issue
VMSA-2015-0006: VMware vCenter Server updates address a LDAP certificate validation issue
VMware vCenter Server LDAP certificate validation vulnerability. VMware vCenter Server does not validate the certificate when connecting to a single sign on identity source using LDAPS (LDAP over SSL). This applies when connecting to Active Directory as an LDAP Server or OpenLDAP. Exploitation of this vulnerability may allow an attacker that is able to intercept traffic between vCenter Server and the LDAP server to capture sensitive information. Active Directory (Integrated Windows Authentication) is unaffected. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2015-6932 to this issue. Column 4 of the following table lists the action required to remediat
GHSA
GHSA-g328-m8jq-63j6: VMware vCenter Server 5
ghsa_unreviewed·2022-05-13
CVE-2015-6932 [MEDIUM] GHSA-g328-m8jq-63j6: VMware vCenter Server 5
VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-18
Published