Vcloud Director
Vendor:
First CVE: Jan 17, 2014 · Active for 12 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vcloud Director over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2014
12 years ago
Most Recent CVE
Apr 14, 2022
1,562 days ago
CVE Severity & Scoring
Vcloud Director5 CVEs
20%
60%
20%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (80.0%)
Unknown1 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High0 (0.0%)
Unknown1 (20.0%)
User Interaction
None3 (60.0%)
Unknown1 (20.0%)
Required1 (20.0%)
Privileges Required
Low1 (20.0%)
High1 (20.0%)
None2 (40.0%)
Unknown1 (20.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-3956HIGH VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vu | May 20, 2020 | 8.8 | 46 | NO | YES |
CVE-2022-22966HIGH An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability t | Apr 14, 2022 | 7.2 | 27 | NO | NO |
CVE-2019-5523CRITICAL VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitatio | Apr 1, 2019 | 9.8 | 25 | NO | NO |
CVE-2016-2076HIGH Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2 | Apr 15, 2016 | 7.6 | 24 | NO | NO |
CVE-2014-1211MEDIUM Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests th | Jan 17, 2014 | 6.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Vcloud Director
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.5.5 | 1 | 7.6 | 1.4% | 0 | 0 |
| 5.1.2 | 1 | 6.8 | 1.3% | 0 | 0 |
| 5.1.1 | 1 | 6.8 | 1.3% | 0 | 0 |
| 5.1.0 | 1 | 6.8 | 1.3% | 0 | 0 |