CVE-2019-5535
published 2019-10-10CVE-2019-5535: VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets. VMware has evaluated the…
PriorityP418medium4.7CVSS 3.1
AVAACLPRNUINSCCNINAL
EPSS
0.48%
38.8th percentile
VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.7.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | >= 11.0.0 < 11.5.0 | 11.5.0 |
| vmware | workstation | >= 15.0.0 < 15.5.0 | 15.5.0 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation, Fusion, VMRC and Horizon Client updates address use-after-free and denial of service vulnerabilities. (CVE-2019-5527, CVE-2019-5535)
vendor_vmware·2019-09-19·CVSS 8.8
CVE-2019-5527 [HIGH] VMware ESXi, Workstation, Fusion, VMRC and Horizon Client updates address use-after-free and denial of service vulnerabilities. (CVE-2019-5527, CVE-2019-5535)
VMSA-2019-0014: VMware ESXi, Workstation, Fusion, VMRC and Horizon Client updates address use-after-free and denial of service vulnerabilities. (CVE-2019-5527, CVE-2019-5535)
| Advisory Severity | Important | CVSSv3 Range | 4.7-8.5 | Synopsis | VMware ESXi, Workstation, Fusion, VMRC and Horizon Client updates address use-after-free and denial of service vulnerabilities. (CVE-2019-5527, CVE-2019-5535) | Issue Date | 2019-09-19 | Updated On | 2019-09-21 | CVE(s) | CVE-2019-5527, CVE-2019-5535 VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation)
CVEs: CVE-2019-5527, CVE-2019-5535
Affected products: Fusion Pro, Horizon Client, VMware ESXi, VMware Fusion, VMware Horizon, VMware Workstation, VMware vSphere, Workstation Pro
GHSA
GHSA-wpc3-hcvp-r9g8: VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets
ghsa_unreviewed·2022-05-24
CVE-2019-5535 [MEDIUM] CWE-20 GHSA-wpc3-hcvp-r9g8: VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets
VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.7.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-10
Published