CVE-2014-3796: Input Validation
Published Sep 15, 2014
·Updated
VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, which allows attackers to obtain sensitive information via unspecified vectors.
Affected Software
17 affected components
VMware Nsx=6.0
VMware Nsx=6.0.1
VMware Nsx=6.0.2
VMware Nsx=6.0.3
VMware Nsx=6.0.4
VMware Nsx=6.0.5
VMware vCloud Networking and Security=5.1
VMware vCloud Networking and Security=5.1.1
VMware vCloud Networking and Security=5.1.2
VMware vCloud Networking and Security=5.1.3
VMware vCloud Networking and Security=5.1.4
VMware vCloud Networking and Security=5.1.4.1
VMware vCloud Networking and Security=5.5
VMware vCloud Networking and Security=5.5.0a
VMware vCloud Networking and Security=5.5.1
VMware vCloud Networking and Security=5.5.2
VMware vCloud Networking and Security=5.5.2.1
Remediation
Event History
Sep 15, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3796?
CVE-2014-3796 is rated as a medium severity vulnerability.
2
How do I fix CVE-2014-3796?
To fix CVE-2014-3796, upgrade to VMware NSX version 6.0.6 or later, or vCloud Networking and Security versions 5.1.4.2 or 5.5.3 or later.
3
What types of products are affected by CVE-2014-3796?
CVE-2014-3796 affects VMware NSX 6.0 through 6.0.5 and vCloud Networking and Security versions 5.1 through 5.5.2.1.
4
What is the impact of exploiting CVE-2014-3796?
Exploiting CVE-2014-3796 may allow attackers to obtain sensitive information.
5
Is there a workaround for CVE-2014-3796?
There are no known workarounds for CVE-2014-3796, so it is recommended to apply the updates.