MEDIUM · 4.0

CVE-2006-5990

VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 cer...

Vulnerability Description

VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 certificate when creating an SSL session, which allows remote malicious servers to spoof valid servers via a man-in-the-middle attack.

CVSS Score

4.0

MEDIUM

AV:N/AC:H/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
VmwareVirtualcenter1.4.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2006-5990?

CVE-2006-5990 is a vulnerability with a CVSS score of 4.0 (MEDIUM). VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 cer...

How severe is CVE-2006-5990?

CVE-2006-5990 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-5990?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Virtualcenter.