CVE-2016-7458

Description

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Risk Information

Base Score
5.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.449

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 5.5Windows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 5.5-u1Windows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 5.5-u2Windows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 5.5-u3aWindows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 5.5-u3bWindows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 6.0Windows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 6.0-2Windows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 6.0-2mWindows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 6.0-aWindows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 6.0-bWindows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 6.0-u1Windows
Vulnerabilities CVE-2016-7458 are affected in VMware VSphere CLI (x64) 6.0-u1bWindows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234