CVE Database
/

CVE-2019-5531

Back to search

CVE-2019-5531

Published: Sep 18, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user’s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.

VendorProductVersions

VMware

VMware vSphere ESXi

affected
6.7 prior to ESXi670-201810101-SG
affected
6.5 prior to ESXi650-201811102-SG
affected
6.0 prior to ESXi600-201807103-SG

VMware

VMware vCenter Server

affected
6.7 prior to 6.7 U1b
affected
6.5 prior to 6.5 U2b
affected
6.0 prior to 6.0 U3j

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now