CVE Vulnerabilities

CVE-2014-8371

Published: Dec 08, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.

Affected Software

NameVendorStart VersionEnd Version
Vcenter_server_applianceVmware5.0-update_1 (including)5.0-update_1 (including)
Vcenter_server_applianceVmware5.0-update_2 (including)5.0-update_2 (including)
Vcenter_server_applianceVmware5.0-update_3 (including)5.0-update_3 (including)
Vcenter_server_applianceVmware5.0-update_3a (including)5.0-update_3a (including)
Vcenter_server_applianceVmware5.1 (including)5.1 (including)
Vcenter_server_applianceVmware5.1-update_1 (including)5.1-update_1 (including)
Vcenter_server_applianceVmware5.1-update_2 (including)5.1-update_2 (including)
Vcenter_server_applianceVmware5.5 (including)5.5 (including)
Vcenter_server_applianceVmware5.5-update_1 (including)5.5-update_1 (including)

References