CVE-2014-1210: VMware Vsphere Client

Medium severity, CVSS 5.8. EPSS: 0.7% chance of exploitation in the next 30 days.

VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

Affected products

  • VMware Vsphere Client: version 5.0 only; version 5.1 only

Published 2014-04-11. Last modified 2026-06-17.