CVE-2013-1661: VMware Esx
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of service (unhandled exception and application crash) by modifying the client-server data stream.
Affected products
- VMware Esx: version 4.0 only; version 4.1 only
- VMware ESXi: version 4.0 only; version 4.1 only; version 5.0 only; version 5.1 only
Published 2013-09-04. Last modified 2026-06-16.