Vulnerability Name: | CVE-2013-5973 (CCN-89938) | ||||||||
Assigned: | 2013-12-22 | ||||||||
Published: | 2013-12-22 | ||||||||
Updated: | 2018-10-09 | ||||||||
Summary: | VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3) -rdmp filename. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-5973 Source: JVN Type: UNKNOWN JVN#13154935 Source: JVNDB Type: UNKNOWN JVNDB-2013-000123 Source: OSVDB Type: UNKNOWN 101387 Source: CCN Type: SA56235 VMware ESX Server / ESXi Virtual Machine File Descriptors Security Bypass Vulnerability Source: CCN Type: OSVDB ID: 101387 VMware ESX / ESXi Unprivileged vCenter Server Arbitrary File Access Source: BUGTRAQ Type: UNKNOWN 20131223 NEW VMSA-2013-0016 VMware ESXi and ESX unauthorized file access through vCenter Server and ESX Source: BID Type: UNKNOWN 64491 Source: CCN Type: BID-64491 VMware ESX and ESXi Virtual Machine File Descriptors Local Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1029529 Source: CCN Type: VMSA-2013-0016 VMware ESXi and ESX unauthorized file access through vCenter Server and ESX Source: CONFIRM Type: Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2013-0016.html Source: XF Type: UNKNOWN vmware-esx-esxi-cve20135973-sec-bypass(89938) Source: XF Type: UNKNOWN vmware-esx-esxi-cve20135973-sec-bypass(89938) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |