CVE-2017-4927
published 2017-11-17CVE-2017-4927: VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.32%
81.5th percentile
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | >= 6.0 < 6.0_u3c | 6.0_u3c |
| vmware | vcenter_server | >= 6.5 < 6.5_u1 | 6.5_u1 |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server update resolves LDAP DoS, SSRF and CRLF injection issues
vendor_vmware·2017-11-09·CVSS 7.5
CVE-2017-4927 [HIGH] VMware vCenter Server update resolves LDAP DoS, SSRF and CRLF injection issues
VMSA-2017-0017: VMware vCenter Server update resolves LDAP DoS, SSRF and CRLF injection issues
a. VMware vCenter Server LDAP Denial of Service (DoS). VMware vCenter Server doesn't correctly handle specially crafted LDAP network packets which may allow for remote DoS. VMware would like to thank Honggang Ren of Fortinet's FortiGuard Labs for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4927 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/ Apply Patch
CVEs: CVE-2017-4927, CVE-2017-4928, CVE-2017-4929
Affected products: VMware vCenter Server, vSp
GHSA
GHSA-wrgq-9j5m-mw73: VMware vCenter Server (6
ghsa_unreviewed·2022-05-17
CVE-2017-4927 [HIGH] CWE-90 GHSA-wrgq-9j5m-mw73: VMware vCenter Server (6
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-11-17
Published