CVE-2010-2928

low VMware
CVSS v3 Base Score
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Score
0.1%
Exploitation probability in 30 days
Top 81% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Confidentiality
P
Integrity
None
Availability
None
Published: February 16, 2011 (5567 days ago)
Last Modified: April 29, 2026
Vendor: VMware
Source: NVD

Description

The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file.

CWE

CWE-255

Affected Products

vmware vcenter server

References