Description
VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of this issue may result in information disclosure.
References (11)
Core 11
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/b1fd306047ecdac82661d636ebee801a7f2b3a0a
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/30ae41bccf418d88b52b35a81efb3c1304b798f8
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/103093
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/756d893573414eec8635c2aba2345c4dcf10b21c
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://seclists.org/oss-sec/2018/q1/153
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/5682ef8d40569afd00fb9a5933e7706bb5b66713
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/ec30db9afada9cb52852082ce4d7d0095524f3b3
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/055ae13603f0cc3cd7cf59f20ce314bf8db583e1
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/c23964eb57e846126daef98ef7ed15400313e977
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/7a747d82b80cd38d2c11a0d9cdedb71c722a2c75
Patch, Third Party Advisory x_refsource_confirm
https://github.com/vmware/xenon/commit/06b9947cf603ba40fd8b03bfeb2e84528a7ab592
Scores
CVSS v3
7.5
EPSS
0.0192
EPSS Percentile
83.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-732
Status
published
Products (7)
vmware/xenon
1.1.0 cr0-3 (2 CPE variants)
vmware/xenon
1.3.7 cr1_2
vmware/xenon
1.4.2 cr4_1
vmware/xenon
1.5.4 cr2 (8 CPE variants)
vmware/xenon
1.5.4_8
vmware/xenon
1.5.7_7
vmware/xenon
1.0.0 - 1.5.3
Published
May 02, 2018
Tracked Since
Feb 18, 2026