CVE-2019-5531

MEDIUM

VMware ESXi and vCenter Server - Insufficient Session Expiration

Title source: llm
STIX 2.1

Description

VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user’s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-613
Status published
Products (6)
vmware/esxi 6.7 670-201811001
vmware/vcenter_server 6.0 (18 CPE variants)
vmware/vcenter_server 6.7 (10 CPE variants)
vmware/vcenter_server 6.5 (16 CPE variants)
vmware/vsphere_esxi 6.7 (2 CPE variants)
vmware/vsphere_esxi 6.5 a (3 CPE variants)
Published Sep 18, 2019
Tracked Since Feb 18, 2026