CVE-2019-5531
published 2019-09-18CVE-2019-5531: VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server…
PriorityP425medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.97%
57.9th percentile
VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user’s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere_esxi | — | — |
| vmware | vmware_vsphere_esxi | — | — |
| vmware | vmware_vsphere_esxi | — | — |
| vmware | vsphere_esxi | — | — |
| vmware | vsphere_esxi | — | — |
| vmware | vsphere_esxi | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534)
vendor_vmware·2019-09-16·CVSS 8.8
CVE-2017-16544 [HIGH] VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534)
VMSA-2019-0013: VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534)
| Advisory Severity | Important | CVSSv3 Range | 4.2-7.7 | Synopsis | VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534) | Issue Date | 2019-09-16 | Updated On | 2019-09-19 | CVE(s) | CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534 VMware vSphere ESXi (ESXi) VMware vCenter Server (vCenter) 2. IntroductionESXi and vCenter updates address multiple vulnerabilities.
CVEs: CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534
Affected products: VMware ESXi, VMware vCenter S
GHSA
GHSA-7623-hj89-p4cw: VMware vSphere ESXi (6
ghsa_unreviewed·2022-05-24
CVE-2019-5531 [MEDIUM] GHSA-7623-hj89-p4cw: VMware vSphere ESXi (6
VMware vSphere ESXi (6.7 prior to ESXi670-201904101-SG, 6.5 prior to ESXi650-201907101-SG, 6.0 prior to ESXi600-201909001) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user?s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-18
Published