VMware Security Updates for vCenter Server (VMSA-2013-0012)

critical Nessus Plugin ID 70612

Synopsis

The remote host has a virtualization management application installed that is affected by multiple vulnerabilities.

Description

The version of VMware vCenter installed on the remote host is 5.0 prior to update 3 or 5.1 prior to update 2. It is, therefore, potentially affected by the following vulnerabilities :

- A vulnerability exists in the handling of session IDs, which could lead to an escalation of privileges.
(CVE-2013-5971)

- Multiple vulnerabilities exists in the bundled version of the Java Runtime Environment.

Solution

Upgrade to VMware vCenter 5.0 update 3, 5.1 update 2 or later.

See Also

https://www.vmware.com/security/advisories/VMSA-2013-0012.html

http://www.nessus.org/u?a094a6d7

Plugin Details

Severity: Critical

ID: 70612

File Name: vmware_vcenter_vmsa-2013-0012.nasl

Version: 1.12

Type: remote

Family: Misc.

Published: 10/25/2013

Updated: 3/29/2022

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.8

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2013-2473

Vulnerability Information

CPE: cpe:/a:vmware:vcenter_server

Required KB Items: Host/VMware/vCenter, Host/VMware/version, Host/VMware/release

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/17/2013

Vulnerability Publication Date: 6/18/2013

CISA Known Exploited Vulnerability Due Dates: 4/18/2022

Exploitable With

Core Impact

Metasploit (Java storeImageArray() Invalid Array Indexing Vulnerability)

Reference Information

CVE: CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437, CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446, CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452, CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457, CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-5971

BID: 60617, 60618, 60619, 60620, 60623, 60624, 60625, 60626, 60627, 60629, 60631, 60632, 60633, 60634, 60636, 60637, 60638, 60639, 60640, 60641, 60643, 60644, 60645, 60646, 60647, 60650, 60651, 60653, 60655, 60656, 60657, 60658, 60659, 63218

VMSA: 2013-0012