VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user’s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: vmware
Published: 2019-09-18T21:42:17
Updated: 2024-08-04T20:01:51.896Z
Reserved: 2019-01-07T00:00:00
Link: CVE-2019-5531

No data.

Status : Modified
Published: 2019-09-18T22:15:11.357
Modified: 2024-11-21T04:45:08.347
Link: CVE-2019-5531

No data.