CVE-2019-5540
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/11/2019
Last modified:
24/08/2020
Description
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.
Impact
Base Score 3.x
7.70
Severity 3.x
HIGH
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | 15.0.0 (including) | 15.5.1 (excluding) |
| cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* | 11.0.0 (including) | 11.5.1 (excluding) |
| cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



