Vulnerability Details CVE-2014-1210
VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.4%
CVSS Severity
CVSS v2 Score 5.8
Products affected by CVE-2014-1210
-
cpe:2.3:a:vmware:vsphere_client:5.0
-
cpe:2.3:a:vmware:vsphere_client:5.1