CVE-2010-2928: Low severity VMware vCenter Server vulnerability
Published Feb 16, 2011
·Updated
The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file.
Affected Software
1 affected component
VMware vCenter Server=4.1
Event History
Feb 16, 2011
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2928?
CVE-2010-2928 has a medium severity level due to the exposure of stored credentials.
2
How do I fix CVE-2010-2928?
To fix CVE-2010-2928, update VMware vCenter Server to at least version 4.1 Update 1.
3
What does CVE-2010-2928 affect?
CVE-2010-2928 affects VMware vCenter Server version 4.1 prior to Update 1.
4
Can local users exploit CVE-2010-2928?
Yes, local users can exploit CVE-2010-2928 by accessing sensitive log-on credentials stored in a configuration file.
5
Is CVE-2010-2928 still a concern for unpatched systems?
Yes, unpatched systems remain vulnerable to CVE-2010-2928, allowing unauthorized privilege escalation.