The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Vmsa 2010 0020 | — | Upgrade VMware ESXi 4.1 to build number 348481 | Feb 24, 2011 | Dec 22, 2010 |
| Vmsa 2011 0003 | — | Apply ESXi410-201101201-SG | Feb 16, 2011 | Dec 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub