CVE-2013-5971

Description

Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.

Risk Information

Base Score
6.3
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.504

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter 4.0.0.10021Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter 4.0.0.12305Windows
Vulnerabilities CVE-2010-2928,CVE-2012-6326,CVE-2013-5971 are affected in VMware vCenter 4.1Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter 4.1.0.12319Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter 4.1.0.14766Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter 4.1.0.17435Windows
Multiple Vulnerabilities are affected in VMware vCenter 5.0Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter 5.0-update_2_rcWindows
Vulnerabilities CVE-2010-2928,CVE-2012-6326,CVE-2013-5971 are affected in VMware vCenter Server 4.1Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 5.0Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter Server 4.0.0.10021Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter Server 4.0.0.12305Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter Server 4.1.0.12319Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter Server 4.1.0.14766Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter Server 4.1.0.17435Windows
Vulnerabilities CVE-2013-5971 are affected in VMware vCenter Server 5.0-update_2_rcWindows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234