CVE-2006-2481
VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using…
Does this matter?
Lower severity and a low EPSS score (7.19%). Track it; it rarely justifies an emergency change on its own.
Description
VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using attacks such as cross-site scripting (CVE-2005-3619).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.19% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- vmware/esx
- Source
- cve@mitre.org
References
- http://kb.vmware.com/kb/2118366
- http://secunia.com/advisories/21230Vendor Advisory
- http://www.corsaire.com/advisories/c060512-001.txtVendor Advisory
- http://www.securityfocus.com/archive/1/441728/100/100/threaded
- http://www.securityfocus.com/archive/1/441825/100/100/threaded
- http://www.securityfocus.com/bid/19249
- http://www.vupen.com/english/advisories/2006/3075Vendor Advisory
- http://kb.vmware.com/kb/2118366
- http://secunia.com/advisories/21230Vendor Advisory
- http://www.corsaire.com/advisories/c060512-001.txtVendor Advisory
- http://www.securityfocus.com/archive/1/441728/100/100/threaded
- http://www.securityfocus.com/archive/1/441825/100/100/threaded
- http://www.securityfocus.com/bid/19249
- http://www.vupen.com/english/advisories/2006/3075Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.