Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-4952

25
FAUCET Score

CVE-2017-4952 describes an authentication bypass vulnerability in various versions of VMware Xenon 1.x, prior to specified patches. This flaw stems from insufficient access controls on utility endpoints, potentially leading to information disclosure. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network without authentication or user interaction, posing a significant risk of data compromise. Despite its severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, <= 1.5.3CPE matchmatch criteria
cpe:2.3:a:vmware:xenon:*:*:*:*:*:*:*:*
1.1.0CPE matchmatch criteria
cpe:2.3:a:vmware:xenon:1.1.0:cr0-3:*:*:*:*:*:*
1.1.0CPE matchmatch criteria
cpe:2.3:a:vmware:xenon:1.1.0:cr3_1:*:*:*:*:*:*
1.3.7CPE matchmatch criteria
cpe:2.3:a:vmware:xenon:1.3.7:cr1_2:*:*:*:*:*:*
1.4.2CPE matchmatch criteria
cpe:2.3:a:vmware:xenon:1.4.2:cr4_1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
3.94%
Probability of exploitation in next 30 days
EPSS Percentile
89.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0394 is in the 81st percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

seclists.org / oss-sec/2018/q1/153
Mailing ListThird Party Advisory
github.com / vmware/xenon/commit/055ae13603f0cc3cd7cf59f20ce314bf8db583e1
PatchThird Party Advisory
github.com / vmware/xenon/commit/06b9947cf603ba40fd8b03bfeb2e84528a7ab592
PatchThird Party Advisory
github.com / vmware/xenon/commit/30ae41bccf418d88b52b35a81efb3c1304b798f8
PatchThird Party Advisory
github.com / vmware/xenon/commit/5682ef8d40569afd00fb9a5933e7706bb5b66713
PatchThird Party Advisory
github.com / vmware/xenon/commit/756d893573414eec8635c2aba2345c4dcf10b21c
PatchThird Party Advisory
github.com / vmware/xenon/commit/7a747d82b80cd38d2c11a0d9cdedb71c722a2c75
PatchThird Party Advisory
github.com / vmware/xenon/commit/b1fd306047ecdac82661d636ebee801a7f2b3a0a
PatchThird Party Advisory
github.com / vmware/xenon/commit/c23964eb57e846126daef98ef7ed15400313e977
PatchThird Party Advisory
github.com / vmware/xenon/commit/ec30db9afada9cb52852082ce4d7d0095524f3b3
PatchThird Party Advisory
securityfocus.com / bid/103093
Third Party AdvisoryVDB Entry