CVE-2009-3733 is a directory traversal vulnerability affecting VMware Server 1.x and 2.x on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5. This flaw allows unauthenticated remote attackers to read arbitrary files on the affected systems. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), it is a medium-severity vulnerability that is easily exploitable over the network with no authentication required, leading to a potential compromise of data confidentiality. While not listed in CISA's KEV catalog, exploit modules are publicly available in Metasploit and ExploitDB, indicating a high potential for exploitation. Despite its age and public exploit code, there is no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.3CPE matchmatch criteria | cpe:2.3:a:vmware:esx:3.0.3:*:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:vmware:esx:3.5:*:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:vmware:esxi:3.5:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:vmware:server:1.0:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:server:1.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.