CIM Server Certificate Validation Issue in VMware vCenter Server Appliance
CVE-2014-8371
Currently unrated
Summary
VMware vCenter Server Appliance falls short in properly validating certificates while connecting to a CIM Server on ESXi hosts. This vulnerability enables man-in-the-middle attackers to effectively spoof CIM servers by using a maliciously crafted certificate, potentially leading to unauthorized access or data interception.
References
Timeline
Vulnerability published
Vulnerability Reserved