CVE-2013-1405: VMware Esx
High severity, CVSS 10.0. EPSS: 2.8% chance of exploitation in the next 30 days.
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Affected products
- VMware Esx: version 3.5 only; version 4.0 only; version 4.1 only
- VMware ESXi: version 3.5 only; version 4.0 only; version 4.1 only
- VMware vCenter Server: version 4.0 only; version 4.1 only
- VMware Vi-Client: version 2.5 only
- VMware Virtualcenter: version 2.5 only
- VMware Vsphere Client: version 4.0 only; version 4.1 only
Published 2013-02-15. Last modified 2026-06-16.