CVE-2014-1210: VMware Vsphere Client
Medium severity, CVSS 5.8. EPSS: 0.7% chance of exploitation in the next 30 days.
VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Affected products
- VMware Vsphere Client: version 5.0 only; version 5.1 only
Published 2014-04-11. Last modified 2026-06-17.