CIM Server Certificate Validation Issue in VMware vCenter Server Appliance
CVE-2014-8371

Currently unrated

Key Information:

Vendor
Vmware
Vendor
CVE Published:
8 December 2014

Summary

VMware vCenter Server Appliance falls short in properly validating certificates while connecting to a CIM Server on ESXi hosts. This vulnerability enables man-in-the-middle attackers to effectively spoof CIM servers by using a maliciously crafted certificate, potentially leading to unauthorized access or data interception.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.