CVE-2017-4923
published 2017-08-01CVE-2017-4923: VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when…
PriorityP346critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.86%
76.8th percentile
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
vendor_vmware·2017-07-27·CVSS 6.7
CVE-2015-5191 [MEDIUM] VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
VMSA-2017-0013: VMware vCenter Server and Tools updates resolve multiple security vulnerabilities
a. Insecure library loading through LD_LIBRARY_PATH VMware vCenter Server contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation. Note: In order to exploit this issue an attacker should be able to trick the admin to execute wrapper scripts from a world writable directory. VMware would like to thank Thorsten Tüllmann, researcher at Karlsruhe Institute of Technology for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4
GHSA
GHSA-29qx-3374-gqm9: VMware vCenter Server (6
ghsa_unreviewed·2022-05-13
CVE-2017-4923 [CRITICAL] CWE-200 GHSA-29qx-3374-gqm9: VMware vCenter Server (6
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-01
Published