Vulnerability Name: | CVE-2013-1661 (CCN-86795) | ||||||||
Assigned: | 2013-08-29 | ||||||||
Published: | 2013-08-29 | ||||||||
Updated: | 2013-09-30 | ||||||||
Summary: | VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of service (unhandled exception and application crash) by modifying the client-server data stream. | ||||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Aug 29 2013 - 23:16:38 CDT NEW VMSA-2013-0011 VMware ESXi and ESX address an NFC Protocol Unhandled Exception Source: MITRE Type: CNA CVE-2013-1661 Source: CCN Type: SA54614 VMware ESXi / ESX Server NFC Protocol Handler Denial of Service Weakness Source: CCN Type: OSVDB ID: 96761 VMware ESX / ESXi Network File Copy (NFC) Traffic Handling DoS Source: CCN Type: BID-62077 VMware ESXi and ESX NFC Protocol Handling Remote Denial of Service Vulnerability Source: CONFIRM Type: Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2013-0011.html Source: CCN Type: VMSA-2013-0011 VMware ESXi and ESX address an NFC Protocol Unhandled Exception - See more at: http://www.vmware.com/support/support-resources/advisories/VMSA-2013-0011.html#sthash.6jz70lDd.dpuf Source: XF Type: UNKNOWN vmware-esxi-cve20131661-dos(86795) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |