CVE-2014-8371: Medium severity vmware vcenter server appliance vulnerability
VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8371?
CVE-2014-8371 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-8371?
To fix CVE-2014-8371, update your VMware vCenter Server Appliance to the latest version or apply the specific patches provided by VMware.
Which VMware products are affected by CVE-2014-8371?
CVE-2014-8371 affects VMware vCenter Server Appliance versions 5.0, 5.1, and 5.5 before their respective update releases.
What type of attack is possible due to CVE-2014-8371?
CVE-2014-8371 enables man-in-the-middle attackers to spoof CIM servers through a crafted certificate.
When was CVE-2014-8371 disclosed?
CVE-2014-8371 was disclosed in December 2014.