CVE-2014-8373
Summary
| CVE | CVE-2014-8373 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-12-11 15:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain privileges via vectors involving the "Connect (by) Using VMRC" function. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Vcloud Automation Center | 6.0.1 | All | All | All |
| Application | Vmware | Vcloud Automation Center | 6.0.1.1 | All | All | All |
| Application | Vmware | Vcloud Automation Center | 6.0.1.2 | All | All | All |
| Application | Vmware | Vcloud Automation Center | 6.1 | All | All | All |
| Application | Vmware | Vcloud Automation Center | 6.1.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware Security Advisory 2014-0013 ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Full Disclosure: NEW VMSA-2014-0013 - VMware vCloud Automation Center product updates address a critical remote privilege escalation vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Security Advisory SA61169 - VMware vCloud Automation Center (vCAC) VMRC Security Bypass Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| VMware vCloud Automation Center Lets Remote Authenticated Users Gain Administrative Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMSA-2014-0013 | United States | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.