CVE-2017-4952: VMware Xenon
High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.
VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of this issue may result in information disclosure.
Affected products
- VMware Xenon: from 1.0.0, up to and including 1.5.3; version 1.1.0 only; version 1.3.7 only; version 1.4.2 only; version 1.5.4 only; version 1.5.4_8 only; …
Published 2018-05-02. Last modified 2026-06-17.