CVE-2013-3107: Medium severity VMware vCenter Server Appliance vulnerability
Published May 1, 2013
·Updated
VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password.
Affected Software
1 affected component
VMware vCenter Server Appliance=5.0
Event History
May 1, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3107?
CVE-2013-3107 is rated as a high severity vulnerability due to its impact on authentication security.
2
How do I fix CVE-2013-3107?
To fix CVE-2013-3107, you should upgrade to VMware vCenter Server 5.1 Update 1 or later.
3
What systems are affected by CVE-2013-3107?
CVE-2013-3107 affects VMware vCenter Server 5.1 before Update 1 and VMware vCenter Server Appliance version 5.0.
4
What is the impact of CVE-2013-3107?
The impact of CVE-2013-3107 allows unauthorized remote access due to authentication bypass vulnerabilities.
5
Is anonymous LDAP binding related to CVE-2013-3107?
Yes, CVE-2013-3107 is specifically related to anonymous LDAP binding for Active Directory being enabled.