CVE-2014-8371
Last modified
CVE-2014-8371 is a vulnerability of currently unknown severity. VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Vmware | Vcenter Server Appliance | 5.0 | Update 1 |
| Vmware | Vcenter Server Appliance | 5.1 | — |
| Vmware | Vcenter Server Appliance | 5.5 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-8371?
How severe is CVE-2014-8371?
How do I fix CVE-2014-8371?
Are you affected by CVE-2014-8371?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
