CVE-2005-3618
| Summary |
Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the administrator via URLs, as demonstrated using the setUsr operation to change a password. NOTE: this issue can be leveraged with CVE-2005-3619 to automatically perform the attacks.
|
| Publication Date |
Dec. 31, 2005, 2 p.m. |
| Registration Date |
Jan. 29, 2021, 5:59 p.m. |
| Last Update |
Oct. 31, 2018, 1:25 a.m. |
|
CVSS2.0 : HIGH
|
| Score |
7.6
|
| Vector |
AV:N/AC:H/Au:N/C:C/I:C/A:C |
| 攻撃元区分(AV) |
ネットワーク |
| 攻撃条件の複雑さ(AC) |
高 |
| 攻撃前の認証要否(Au) |
不要 |
| 機密性への影響(C) |
高 |
| 完全性への影響(I) |
高 |
| 可用性への影響(A) |
高 |
| Get all privileges. |
はい
|
| Get user privileges |
いいえ
|
| Get other privileges |
いいえ
|
| User operation required |
はい
|
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:vmware:esx:*:*:*:*:*:*:*:* |
2.0.1 |
|
|
2.0.2 |
| cpe:2.3:o:vmware:esx:*:*:*:*:*:*:*:* |
2.1.1 |
|
|
2.1.3 |
| cpe:2.3:o:vmware:esx:*:*:*:*:*:*:*:* |
2.5.2 |
|
|
2.5.3 |
Related information, measures and tools
Common Vulnerabilities List