CVE-2013-3107: VMware vCenter Server Appliance

Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.

VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password.

Affected products

  • VMware vCenter Server Appliance: version 5.0 only

Published 2013-05-01. Last modified 2026-06-16.