CVE-2014-8371: VMware vCenter Server Appliance
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.
Affected products
- VMware vCenter Server Appliance: version 5.0 only; version 5.1 only; version 5.5 only
Published 2014-12-08. Last modified 2026-06-17.