VulnerabilityModified
CVE-2013-3520
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.
HIGH 7.5EPSS 55.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 55.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 55.64% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- vmware/vcenter chargeback manager
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.