CVE-2013-3107

VMware vCenter Server <5.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password.

References (1)

Core 1
Core References

Scores

EPSS 0.0011
EPSS Percentile 29.6%

Details

CWE
CWE-264
Status published
Products (1)
vmware/vcenter_server_appliance 5.0
Published May 01, 2013
Tracked Since Feb 18, 2026