Back
CVE-2005-3618
Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the administrator via URLs, as demonstrated using the setUsr operation to change a password. NOTE: this issue can be leveraged with CVE-2005-3619 to automatically perform the attacks.
Published: Dec 31, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| vmware | esx | * ≥ 2.0.1 < 2.0.2 |
| vmware | esx | * ≥ 2.1.1 < 2.1.3 |
| vmware | esx | * ≥ 2.5.2 < 2.5.3 |
GitHub Security Advisory GHSA-h6c2-g6q9-7g8w
Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server...
References (14)
- http://kb.vmware.com/kb/2118366 Vendor Advisory
- http://secunia.com/advisories/21230 Third Party Advisory
- http://securitytracker.com/id?1016612 Third Party Advisory, VDB Entry
- http://www.corsaire.com/advisories/c051114-001.txt Broken Link
- http://www.securityfocus.com/archive/1/441726/100/100/threaded
- http://www.securityfocus.com/archive/1/441825/100/100/threaded
- http://www.vupen.com/english/advisories/2006/3075 Permissions Required, Third Party Advisory
- http://kb.vmware.com/kb/2118366 Vendor Advisory
- http://secunia.com/advisories/21230 Third Party Advisory
- http://securitytracker.com/id?1016612 Third Party Advisory, VDB Entry
- http://www.corsaire.com/advisories/c051114-001.txt Broken Link
- http://www.securityfocus.com/archive/1/441726/100/100/threaded
- http://www.securityfocus.com/archive/1/441825/100/100/threaded
- http://www.vupen.com/english/advisories/2006/3075 Permissions Required, Third Party Advisory
Risk Scores
CVSS Score
7.6 / 10
EPSS Score
3.01%
Top 14% most likely to be exploited
Threat Score
31.3 / 100
Data Sources
NVD
EPSS
GitHub