{"api_version":"1","generated_at":"2026-07-23T10:17:01+00:00","cve":"CVE-2017-4927","urls":{"html":"https://cve.report/CVE-2017-4927","api":"https://cve.report/api/cve/CVE-2017-4927.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-4927","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-4927"},"summary":{"title":"CVE-2017-4927","description":"VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.","state":"PUBLIC","assigner":"security@vmware.com","published_at":"2017-11-17 14:29:00","updated_at":"2017-12-04 16:30:00"},"problem_types":["CWE-90"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/101786","name":"101786","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"VMware vCenter Server CVE-2017-4927 Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1039759","name":"1039759","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"VMware vCenter Server Flaws Let Remote Users Deny Service and Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.vmware.com/security/advisories/VMSA-2017-0017.html","name":"https://www.vmware.com/security/advisories/VMSA-2017-0017.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"VMSA-2017-0017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-4927","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-4927","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"4927","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"vcenter_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"4927","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"vcenter_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@vmware.com","DATE_PUBLIC":"2017-11-09T00:00:00","ID":"CVE-2017-4927","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"vCenter Server","version":{"version_data":[{"version_value":"6.5 prior to 6.5 U1"},{"version_value":"6.0 prior to 6.0 U3c"}]}}]},"vendor_name":"VMware"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"LDAP denial of service vulnerability"}]}]},"references":{"reference_data":[{"name":"https://www.vmware.com/security/advisories/VMSA-2017-0017.html","refsource":"CONFIRM","url":"https://www.vmware.com/security/advisories/VMSA-2017-0017.html"},{"name":"1039759","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039759"},{"name":"101786","refsource":"BID","url":"http://www.securityfocus.com/bid/101786"}]}},"nvd":{"publishedDate":"2017-11-17 14:29:00","lastModifiedDate":"2017-12-04 16:30:00","problem_types":["CWE-90"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.5_u1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.0_u3c","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"4927","Ordinal":"101357","Title":"CVE-2017-4927","CVE":"CVE-2017-4927","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"4927","Ordinal":"1","NoteData":"VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"4927","Ordinal":"2","NoteData":"2017-11-17","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"4927","Ordinal":"3","NoteData":"2017-11-18","Type":"Other","Title":"Modified"}]}}}