First published: Wed Dec 22 2010(Updated: )
The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ESXi | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4573 is considered a critical vulnerability due to the potential for unauthorized remote access.
To fix CVE-2010-4573, ensure the sfcb.cfg file is not modified and follow VMware's security updates for ESXi 4.1.
CVE-2010-4573 affects VMware ESXi version 4.1.
Yes, CVE-2010-4573 allows attackers to gain unauthorized access via arbitrary credentials.
Yes, CVE-2010-4573 is exploitable remotely due to its configuration vulnerabilities.