CVE-2017-4928 describes Server-Side Request Forgery (SSRF) and CRLF injection vulnerabilities in the flash-based vSphere Web Client (versions 6.0 prior to U3c and 5.5 prior to U3f) of VMware vCenter Server. An unauthenticated attacker can exploit these flaws by sending crafted POST requests with modified headers to internal services, leading to information disclosure. With a CVSS v3 score of 7.5 (High), this vulnerability is network-exploitable with low attack complexity and no user interaction required, potentially resulting in significant confidentiality impact. While not listed in CISA's KEV catalog, there is limited public exploit intelligence, with no Metasploit or ExploitDB modules, but it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:5.5:*:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:5.5:1:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:5.5:1a:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:5.5:1b:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:5.5:1c:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.