Vcenter Server Appliance
Vendor:
First CVE: Dec 21, 2012 · Active for 13 years
14
Total CVEs
More Total CVEs than 92% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 38% of tracked products
14.3%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Vcenter Server Appliance over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2012
13 years ago
Most Recent CVE
Dec 8, 2014
4,250 days ago
CVE Severity & Scoring
Vcenter Server Appliance14 CVEs
50%
36%
14%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (14.3%)
Unknown12 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (14.3%)
High0 (0.0%)
Unknown12 (85.7%)
User Interaction
None2 (14.3%)
Unknown12 (85.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (14.3%)
Unknown12 (85.7%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2013-3080HIGH VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or caus | May 1, 2013 | 9.0 | 27 | NO | NO |
CVE-2013-3079HIGH VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Mana | May 1, 2013 | 9.0 | 26 | NO | NO |
CVE-2013-1659HIGH VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Ne | Feb 22, 2013 | 7.6 | 26 | NO | NO |
CVE-2014-3790HIGH Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail. | Jun 1, 2014 | 9.0 | 23 | NO | NO |
CVE-2012-6326HIGH VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors | Feb 22, 2013 | 7.8 | 23 | NO | NO |
CVE-2014-4258MEDIUM Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integ | Jul 17, 2014 | 6.5 | 18 | NO | NO |
CVE-2012-6324MEDIUM Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via | Dec 21, 2012 | 4.0 | 18 | NO | NO |
CVE-2012-6325MEDIUM VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified ve | Dec 21, 2012 | 4.0 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
2 CVEs
14.3% of CVEs· 99th percentile
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
1 CVE
7.1% of CVEs· 97th percentile
ExploitDB
2 CVEs
14.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Vcenter Server Appliance
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.5 | 5 | 7.8 | 45.6% | 2 | 2 |
| 5.1.0a | 1 | 7.6 | 1.8% | 0 | 0 |
| 5.1 | 11 | 7.0 | 30.0% | 2 | 2 |
| 5.0 | 8 | 6.6 | 31.1% | 2 | 2 |