CVE-2013-1659

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.

References

http://www.vmware.com/security/advisories/VMSA-2013-0003.html

Details

Source: MITRE

Published: 2013-02-22

Updated: 2013-02-25

Risk Information

CVSS v2

Base Score: 7.6

Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 4.9

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:vmware:vcenter_server:4.0:*:*:*:*:*:*:*

cpe:2.3:a:vmware:vcenter_server:4.0:update_1:*:*:*:*:*:*

cpe:2.3:a:vmware:vcenter_server:4.0:update_2:*:*:*:*:*:*

cpe:2.3:a:vmware:vcenter_server:4.0:update_3:*:*:*:*:*:*

cpe:2.3:a:vmware:vcenter_server:4.0:update_4:*:*:*:*:*:*

cpe:2.3:a:vmware:vcenter_server:4.0:update_4a:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:vmware:vcenter_server_appliance:5.1:*:*:*:*:*:*:*

cpe:2.3:a:vmware:vcenter_server_appliance:5.1.0a:*:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:a:vmware:vcenter_server:5.0:*:*:*:*:*:*:*

cpe:2.3:a:vmware:vcenter_server:5.0:update_1:*:*:*:*:*:*

Configuration 4

OR

cpe:2.3:o:vmware:esxi:3.5:*:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:3.5:1:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:1:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:2:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:3:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:4:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.1:*:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.1:1:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.1:2:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:5.0:*:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:5.0:1:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:5.0:2:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:5.1:*:*:*:*:*:*:*

Configuration 5

OR

cpe:2.3:o:vmware:esxi:3.5:*:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:3.5:1:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:1:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:2:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:3:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.0:4:*:*:*:*:*:*

cpe:2.3:o:vmware:esxi:4.1:*:*:*:*:*:*:*

Tenable Plugins

View all (5 total)

IDNameProductFamilySeverity
89663VMware ESX / ESXi NFC and Third-Party Libraries Multiple Vulnerabilities (VMSA-2013-0003) (remote check)NessusMisc.
critical
70888ESXi 5.1 < Build 911593 Multiple Vulnerabilities (remote check)NessusMisc.
high
70885ESXi 5.0 < Build 912577 Multiple Vulnerabilities (remote check)NessusMisc.
high
65223VMware vCenter Server NFC Protocol Code Execution (VMSA-2013-0003)NessusMisc.
high
64812VMSA-2013-0003 : VMware vCenter Server, ESXi and ESX address an NFC Protocol memory corruption and third-party library security issues.NessusVMware ESX Local Security Checks
high