CVE-2019-5523 is a critical remote session hijack vulnerability affecting VMware vCloud Director for Service Providers versions 9.5.x prior to 9.5.0.3. An unauthenticated attacker can exploit this flaw to impersonate a logged-in user and gain unauthorized access to the Tenant or Provider Portals. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered significant community and media attention, indicating its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.5.0.0, < 9.5.0.3CPE matchmatch criteria | cpe:2.3:a:vmware:vcloud_director:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.