Vcenter Server

Vendor:

First CVE: Mar 25, 2009 · Active for 17 years

79
Total CVEs
More Total CVEs than 99% of tracked products
6.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
13.9%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Vcenter Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2009
17 years ago
Most Recent CVE
Sep 17, 2024
675 days ago

CVE Severity & Scoring

Vcenter Server79 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local8 (10.1%)
Network61 (77.2%)
Unknown10 (12.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low65 (82.3%)
High4 (5.1%)
Unknown10 (12.7%)
User Interaction
None61 (77.2%)
Unknown10 (12.7%)
Required8 (10.1%)
Privileges Required
Low19 (24.1%)
High4 (5.1%)
None46 (58.2%)
Unknown10 (12.7%)

Top CVEs

Signals from CVEs in this product scope (79 CVEs).

79 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to ex
Feb 24, 20219.899YESYES
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou
Oct 25, 20239.898YESYES
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this is
Sep 23, 20219.898YESYES
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCe
May 26, 20219.898YESYES
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access co
Apr 10, 20209.898YESYES
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with networ
Feb 24, 20215.394YESYES
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vul
Sep 17, 20249.890YESNO
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Serve
Sep 23, 20215.387YESYES
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attacker
Oct 12, 201510.087NOYES
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnera
Jun 18, 20249.880YESNO

Exploit Exposure

Signals from CVEs in this product scope (79 CVEs).

CISA KEV
11 CVEs
13.9% of CVEs· 98th percentile
Metasploit
8 CVEs
10.1% of CVEs· 97th percentile
Nuclei
7 CVEs
8.9% of CVEs· 97th percentile
ExploitDB
4 CVEs
5.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (79 CVEs).

Media Mentions

Signals from CVEs in this product scope (79 CVEs).

Top CNAs Publishing CVEs For Vcenter Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0158.316.8%42
7.0438.119.1%98
6.7377.022.3%78
6.5347.221.2%56
6.097.12.6%01
5.5107.03.6%01
5.156.319.6%01
5.097.18.1%01
4.1.0.1743516.82.0%00
4.1.0.1476616.82.0%00
4.1.0.1231916.82.0%00
4.147.01.5%00
4.0.0.1230516.82.0%00
4.0.0.1002116.82.0%00
4.057.52.3%01