Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
Name CVE-2014-1211 First vendor Publication 2014-01-17
Vendor Cve Last vendor Modification 2017-08-29

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1211

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-352 Cross-Site Request Forgery (CSRF) (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 3

Information Assurance Vulnerability Management (IAVM)

Date Description
2014-01-31 IAVM : 2014-B-0008 - Multiple Vulnerabilities in VMware ESX 4.0 and ESXi 4.0
Severity : Category I - VMSKEY : V0043879
2014-01-31 IAVM : 2014-B-0009 - Multiple Vulnerabilities in VMware ESX 4.1 and ESXi 4.1
Severity : Category I - VMSKEY : V0043880
2014-01-31 IAVM : 2014-B-0010 - Multiple Vulnerabilities in VMware ESXi 5.1
Severity : Category I - VMSKEY : V0043881
2014-01-30 IAVM : 2014-A-0019 - Multiple Vulnerabilities in VMware Fusion
Severity : Category I - VMSKEY : V0043844
2013-11-21 IAVM : 2013-A-0221 - Multiple Vulnerabilties in VMware Player
Severity : Category II - VMSKEY : V0042382
2013-11-21 IAVM : 2013-A-0222 - Multiple Vulnerabilties in VMware Workstation
Severity : Category II - VMSKEY : V0042383
2013-10-31 IAVM : 2013-A-0205 - VMware ESXi 5.0 Denial of Service Vulnerability
Severity : Category I - VMSKEY : V0041367

Nessus® Vulnerability Scanner

Date Description
2015-12-30 Name : The remote VMware ESX / ESXi host is missing a security-related patch.
File : vmware_VMSA-2014-0001_remote.nasl - Type : ACT_GATHER_INFO
2014-11-26 Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2014-0001.nasl - Type : ACT_GATHER_INFO
2014-01-24 Name : A virtualization appliance installed on the remote host is affected by a cros...
File : vmware_vcloud_director_vmsa-2014-0001.nasl - Type : ACT_GATHER_INFO
2014-01-20 Name : The remote host has a virtualization application that is affected by a denial...
File : macosx_fusion_5_0_1.nasl - Type : ACT_GATHER_INFO
2014-01-20 Name : The remote VMware ESXi 5.1 host is affected by multiple vulnerabilities.
File : vmware_esxi_5_1_build_1483097_remote.nasl - Type : ACT_GATHER_INFO
2014-01-20 Name : The remote host has a virtualization application that is affected by a denial...
File : vmware_player_dos_vmsa_2014_0001.nasl - Type : ACT_GATHER_INFO
2014-01-20 Name : The remote host has a virtualization application that is affected by a denial...
File : vmware_player_linux_5_0_1.nasl - Type : ACT_GATHER_INFO
2014-01-20 Name : The remote host has a virtualization application that is affected by a denial...
File : vmware_workstation_dos_vmsa_2014_0001.nasl - Type : ACT_GATHER_INFO
2014-01-20 Name : The remote host has a virtualization application that is affected by a denial...
File : vmware_workstation_linux_9_0_1.nasl - Type : ACT_GATHER_INFO
2014-01-17 Name : The remote VMware ESXi / ESX host is missing a security-related patch.
File : vmware_VMSA-2014-0001.nasl - Type : ACT_GATHER_INFO
2013-11-13 Name : The remote VMware ESXi 5.0 host is affected by multiple security vulnerabilit...
File : vmware_esxi_5_0_build_1311177_remote.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/64993
CONFIRM http://www.vmware.com/security/advisories/VMSA-2014-0001.html
OSVDB http://osvdb.org/102198
SECTRACK http://www.securitytracker.com/id/1029645
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/90560

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
Date Informations
2021-05-04 12:29:43
  • Multiple Updates
2021-04-22 01:35:59
  • Multiple Updates
2020-05-23 00:39:47
  • Multiple Updates
2017-08-29 09:24:27
  • Multiple Updates
2016-06-28 22:33:52
  • Multiple Updates
2014-02-17 11:25:09
  • Multiple Updates
2014-01-30 13:21:06
  • Multiple Updates
2014-01-24 13:19:52
  • Multiple Updates
2014-01-22 13:19:14
  • Multiple Updates
2014-01-18 13:19:38
  • First insertion