Vulnerability Details CVE-2005-3618
                Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the administrator via URLs, as demonstrated using the setUsr operation to change a password.  NOTE: this issue can be leveraged with CVE-2005-3619 to automatically perform the attacks.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.021
                        
                    
                    
                        
                            EPSS Ranking 83.7%
                        
                    
                 
                
                    CVSS Severity
                    
                    
                        
                            CVSS v2 Score 7.6
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2005-3618
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:vmware:esx:2.0.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:vmware:esx:2.1.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:vmware:esx:2.1.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:vmware:esx:2.5.2