CVE-2015-6932
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
18/09/2015
Last modified:
12/04/2025
Description
VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Impact
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:vmware:vcenter_server:5.5:-:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:5.5:1:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:5.5:1a:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:5.5:1b:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:5.5:1c:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:5.5:2:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:5.5:2b:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:5.5:2d:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:5.5:2e:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:6.0:-:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:6.0:a:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vcenter_server:6.0:b:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page