SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-3589

vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the…

LOW 3.6EPSS 0.43%

Does this matter?

Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.

Description

vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.

CVSS 2.0
3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
EPSS
0.43% probability · 36th percentile
CISA KEV
Not listed
Affected
vmware/infrastructure · vmware/player · vmware/server · vmware/workstation · vmware/esx
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.