The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.
References
Configurations
Information
Published : 2010-12-22 13:00
Updated : 2018-10-10 13:08
NVD link : CVE-2010-4573
Mitre link : CVE-2010-4573
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
vmware
- esxi