Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-1210

Overview

Vulnerability Score 5.8 5.8
CVE Id CVE-2014-1210
Last Modified 14 Apr 2014 12:58:12
Published 11 Apr 2014 03:55:04
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2014-1210

Summary

VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

Vulnerable Systems

Application

  • Vmware Vsphere Client 5.0

  • Vmware Vsphere Client 5.1


References

CONFIRM - http://www.vmware.com/security/advisories/VMSA-2014-0003.html


Last Updated: 27 May 2016 11:04:56