CVE-2005-3620
The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users…
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to gain privileges.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Affected
- vmware/esx
- Source
- cve@mitre.org
References
- http://kb.vmware.com/kb/2118366Vendor Advisory
- http://secunia.com/advisories/21230Third Party Advisory
- http://www.corsaire.com/advisories/c051114-003.txtBroken Link
- http://www.kb.cert.org/vuls/id/822476Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/441727/100/100/threaded
- http://www.securityfocus.com/archive/1/441825/100/100/threaded
- http://www.securityfocus.com/bid/19249Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/3075Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28112Third Party Advisory, VDB Entry
- http://kb.vmware.com/kb/2118366Vendor Advisory
- http://secunia.com/advisories/21230Third Party Advisory
- http://www.corsaire.com/advisories/c051114-003.txtBroken Link
- http://www.kb.cert.org/vuls/id/822476Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/441727/100/100/threaded
- http://www.securityfocus.com/archive/1/441825/100/100/threaded
- http://www.securityfocus.com/bid/19249Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/3075Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28112Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.