Vulnerability Name:

CVE-2019-5531 (CCN-167100)

Assigned:2019-09-16
Published:2019-09-16
Updated:2020-02-10
Summary:VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user’s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.
CVSS v3 Severity:5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
4.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
4.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-613
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2019-5531

Source: CONFIRM
Type: UNKNOWN
http://www.vmware.com/security/advisories/VMSA-2019-0013.html

Source: XF
Type: UNKNOWN
vmware-cve20195531-info-disc(167100)

Source: CCN
Type: VMware Security Advisory VMSA-2019-0013
VMware Security Advisories

Vulnerable Configuration:Configuration 1:
  • cpe:/o:vmware:esxi:6.7:670-201811001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.7:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.7:update_1:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:vmware:vsphere_esxi:6.5:a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vsphere_esxi:6.5:u2:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.5:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.5:650-201810002:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.5:650-201811001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.5:650-201811002:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.5:650-201901001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.5:650-201903001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.5:650-201905001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.5:update_1:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:vmware:vsphere_esxi:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:600-201810001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:600-201811001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:600-201903001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:600-201905001:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:beta:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:u1a:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:u1b:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:u3a:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:update_2:*:*:*:*:*:*
  • OR cpe:/o:vmware:vsphere_esxi:6.0:update_3:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:vmware:vcenter_server:6.0:-:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:1:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:1b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update2:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update2a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update2m:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:u3:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3e:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3f:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3g:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3h:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.0:update3i:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/a:vmware:vcenter_server:6.7:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/a:vmware:vcenter_server:6.5:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:vmware:esxi:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    vmware esxi 6.7 670-201811001
    vmware vsphere esxi 6.7
    vmware vsphere esxi 6.7 update_1
    vmware vsphere esxi 6.5 a
    vmware vsphere esxi 6.5 u2
    vmware vsphere esxi 6.5
    vmware vsphere esxi 6.5 650-201810002
    vmware vsphere esxi 6.5 650-201811001
    vmware vsphere esxi 6.5 650-201811002
    vmware vsphere esxi 6.5 650-201901001
    vmware vsphere esxi 6.5 650-201903001
    vmware vsphere esxi 6.5 650-201905001
    vmware vsphere esxi 6.5 update_1
    vmware vsphere esxi 6.0
    vmware vsphere esxi 6.0 600-201810001
    vmware vsphere esxi 6.0 600-201811001
    vmware vsphere esxi 6.0 600-201903001
    vmware vsphere esxi 6.0 600-201905001
    vmware vsphere esxi 6.0 beta
    vmware vsphere esxi 6.0 u1a
    vmware vsphere esxi 6.0 u1b
    vmware vsphere esxi 6.0 u3a
    vmware vsphere esxi 6.0 update_2
    vmware vsphere esxi 6.0 update_3
    vmware vcenter server 6.0
    vmware vcenter server 6.0 a
    vmware vcenter server 6.0 b
    vmware vcenter server 6.0 u1
    vmware vcenter server 6.0 u1b
    vmware vcenter server 6.0 u2
    vmware vcenter server 6.0 u2a
    vmware vcenter server 6.0 u2m
    vmware vcenter server 6.0 u3
    vmware vcenter server 6.0 u3a
    vmware vcenter server 6.0 u3b
    vmware vcenter server 6.0 u3c
    vmware vcenter server 6.0 u3d
    vmware vcenter server 6.0 u3e
    vmware vcenter server 6.0 u3f
    vmware vcenter server 6.0 u3g
    vmware vcenter server 6.0 u3h
    vmware vcenter server 6.0 u3i
    vmware vcenter server 6.7
    vmware vcenter server 6.7 a
    vmware vcenter server 6.7 b
    vmware vcenter server 6.7 c
    vmware vcenter server 6.7 d
    vmware vcenter server 6.7 u1
    vmware vcenter server 6.7 u1b
    vmware vcenter server 6.7 u2
    vmware vcenter server 6.7 u2a
    vmware vcenter server 6.7 u2c
    vmware vcenter server 6.5
    vmware vcenter server 6.5 a
    vmware vcenter server 6.5 b
    vmware vcenter server 6.5 c
    vmware vcenter server 6.5 d
    vmware vcenter server 6.5 u1
    vmware vcenter server 6.5 u1b
    vmware vcenter server 6.5 u1c
    vmware vcenter server 6.5 u1d
    vmware vcenter server 6.5 u1e
    vmware vcenter server 6.5 u1g
    vmware vcenter server 6.5 u2
    vmware vcenter server 6.5 u2b
    vmware vcenter server 6.5 u2c
    vmware vcenter server 6.5 u2d
    vmware vcenter server 6.5 u2g
    vmware esxi 6.0
    vmware esxi 6.5
    vmware esxi 6.7