CVE-2010-0686 is a URL forwarding vulnerability affecting the WebAccess component of legacy VMware VirtualCenter, Server, and ESX products, which allows remote attackers to spoof request origins by abusing proxy-server functionality. This high-severity issue, rated CVSS 7.5, stems from improper input validation and is exploitable via the network without authentication, presenting risks to data confidentiality, integrity, and availability. Despite its severity, there are no known public exploits, active campaigns, or listings in the CISA Known Exploited Vulnerabilities catalog associated with this defect.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.2CPE matchmatch criteria | cpe:2.3:a:vmware:virtualcenter:2.0.2:*:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:a:vmware:virtualcenter:2.5:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:server:2.0.0:*:*:*:*:*:*:* | ||
3.0.3CPE matchmatch criteria | cpe:2.3:a:vmware:esx_server:3.0.3:*:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:vmware:esx_server:3.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.