SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-7458

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML…

MEDIUM 5.8EPSS 1.23%

Does this matter?

Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.

Description

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS 3.0
5.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
EPSS
1.23% probability · 67th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
vmware/vsphere client
Source
security@vmware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.