cbcvebase.
CVE-2017-4940
published 2017-12-20

CVE-2017-4940: The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a…

PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.91%
56.0th percentile
The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when other users access the Host Client.

Affected

14 ranges
VendorProductVersion rangeFixed in
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwareesxi
vmwarefusion_pro
vmwarevmware_esxi
vmwarevmware_fusion
vmwarevmware_vcenter_server
vmwarevmware_workstation
vmwarevsphere
vmwareworkstation_player
vmwareworkstation_pro

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.