VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vcenter_server_appliance | Vmware | 5.0-update_1 (including) | 5.0-update_1 (including) |
Vcenter_server_appliance | Vmware | 5.0-update_2 (including) | 5.0-update_2 (including) |
Vcenter_server_appliance | Vmware | 5.0-update_3 (including) | 5.0-update_3 (including) |
Vcenter_server_appliance | Vmware | 5.0-update_3a (including) | 5.0-update_3a (including) |
Vcenter_server_appliance | Vmware | 5.1 (including) | 5.1 (including) |
Vcenter_server_appliance | Vmware | 5.1-update_1 (including) | 5.1-update_1 (including) |
Vcenter_server_appliance | Vmware | 5.1-update_2 (including) | 5.1-update_2 (including) |
Vcenter_server_appliance | Vmware | 5.5 (including) | 5.5 (including) |
Vcenter_server_appliance | Vmware | 5.5-update_1 (including) | 5.5-update_1 (including) |