cbcvebase.

Vmware Vcenter Server vulnerabilities

81 known vulnerabilities affecting vmware/vcenter_server.

Total CVEs
81
CISA KEV
11
actively exploited
Public exploits
15
Exploited in wild
13
Severity breakdown
CRITICAL20HIGH29MEDIUM31LOW1

Vulnerabilities

Page 3 of 5
CVE-2019-5532P3HIGHCVSS 7.7v6.0v6.7+4 more2019-09-18
CVE-2019-5532 [HIGH] CWE-532 CVE-2019-5532: VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF m
nvd
CVE-2021-22013P3HIGHCVSS 7.5v6.7v7.02021-09-23
CVE-2021-22013 [HIGH] CWE-22 CVE-2021-22013: The vCenter Server contains a file path traversal vulnerability leading to information disclosure in The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
nvd
CVE-2019-5534P3HIGHCVSS 7.7v6.0v6.7+4 more2019-09-18
CVE-2019-5534 [HIGH] CWE-200 CVE-2019-5534: VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig properties. A malicious actor with access to query the vAppConfig properties of a virtual machine depl
nvd
CVE-2021-22019P3HIGHCVSS 7.5v6.5v6.7+1 more2021-09-23
CVE-2021-22019 [HIGH] CVE-2021-22019: The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malic The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial of service condition.
nvd
CVE-2013-1659P3HIGHCVSS 7.6v4.0v5.02013-02-22
CVE-2013-1659 [HIGH] CVE-2013-1659: VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data
nvd
CVE-2021-21991P3HIGHCVSS 7.8v6.5v6.7+1 more2021-09-22
CVE-2021-21991 [HIGH] CVE-2021-21991: The vCenter Server contains a local privilege escalation vulnerability due to the way it handles ses The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash).
nvd
CVE-2020-3994P3HIGHCVSS 7.4v6.5v6.7+1 more2020-10-20
CVE-2020-3994 [HIGH] CWE-295 CVE-2020-3994: VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCente
nvd
CVE-2017-4928P3HIGHCVSS 7.5v5.5v6.02017-11-17
CVE-2017-4928 [HIGH] CWE-352 CVE-2017-4928: The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.
nvd
CVE-2023-20896P3HIGHCVSS 7.5≥ 4.0, < 7.0v7.0+1 more2023-06-22
CVE-2023-20896 [HIGH] CWE-125 CVE-2023-20896: The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).
nvd
CVE-2017-4927P3HIGHCVSS 7.5≥ 6.0, < 6.0_u3c≥ 6.5, < 6.5_u1+2 more2017-11-17
CVE-2017-4927 [HIGH] CWE-90 CVE-2017-4927: VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle speci VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
nvd
CVE-2021-22010P3HIGHCVSS 7.5v6.7v7.02021-09-23
CVE-2021-22010 [HIGH] CWE-400 CVE-2021-22010: The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor wit The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create a denial of service condition due to excessive memory consumption by VPXD service.
nvd
CVE-2017-4943P3HIGHCVSS 7.8v6.52017-12-20
CVE-2017-4943 [HIGH] CWE-787 CVE-2017-4943: VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vu VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.
nvd
CVE-2021-22018P3MEDIUMCVSS 6.5v7.02021-09-23
CVE-2021-22018 [MEDIUM] CVE-2021-22018: The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.
nvd
CVE-2021-22009P3HIGHCVSS 7.5v6.7v7.02021-09-23
CVE-2021-22009 [HIGH] CWE-668 CVE-2021-22009: The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory consumption by VAPI service.
nvd
CVE-2021-21993P3MEDIUMCVSS 6.5v6.5v6.7+1 more2021-09-23
CVE-2021-21993 [MEDIUM] CWE-918 CVE-2021-21993: The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper vali The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to information disclosure.
nvd
CVE-2016-2076P4HIGHCVSS 7.6≤ 6.0v5.52016-04-15
CVE-2016-2076 [HIGH] CWE-287 CVE-2016-2076: Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vC Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
nvd
CVE-2013-5971P4MEDIUMCVSS 6.8≤ 5.0v4.0.0.10021+6 more2013-10-21
CVE-2013-5971 [MEDIUM] CWE-264 CVE-2013-5971: Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
nvd
CVE-2017-4922P4MEDIUMCVSS 6.5v6.52017-08-01
CVE-2017-4922 [MEDIUM] CWE-200 CVE-2017-4922: VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the serv VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
nvd
CVE-2021-21992P4MEDIUMCVSS 6.5v6.5v6.7+1 more2021-09-22
CVE-2021-21992 [MEDIUM] CVE-2021-21992: The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create a denial-of-service condition on the vCenter Server host.
nvd
CVE-2021-22011P4MEDIUMCVSS 5.3v6.5v6.7+1 more2021-09-23
CVE-2021-22011 [MEDIUM] CVE-2021-22011: vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Libr vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.
nvd
Vmware Vcenter Server vulnerabilities | cvebase