CVE-2017-4927
Estado: ModificadaAlta (7.5)—
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.32%
- Percentil entre todas las CVEs puntuadas: 83
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-90
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-4927",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@vmware.com",
"affectedData": [
{
"vendor": "VMware",
"product": "vCenter Server",
"versions": [
{
"status": "affected",
"version": "6.5 prior to 6.5 U1"
},
{
"status": "affected",
"version": "6.0 prior to 6.0 U3c"
}
]
}
]
}
],
"published": "2017-11-17T14:29:00.450",
"references": [
{
"url": "http://www.securityfocus.com/bid/101786",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security@vmware.com"
},
{
"url": "http://www.securitytracker.com/id/1039759",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security@vmware.com"
},
{
"url": "https://www.vmware.com/security/advisories/VMSA-2017-0017.html",
"tags": [
"Vendor Advisory"
],
"source": "security@vmware.com"
},
{
"url": "http://www.securityfocus.com/bid/101786",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1039759",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.vmware.com/security/advisories/VMSA-2017-0017.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-90"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service."
},
{
"lang": "es",
"value": "VMware vCenter Server (en versiones 6.5 anteriores a la 6.5 U1 y versiones 6.0 anteriores a la 6.0 U3c) no gestiona correctamente paquetes de red LDAP especialmente manipulados, lo que puede permitir que se provoque una denegación de servicio de forma remota."
}
],
"lastModified": "2026-06-17T01:19:34.783",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4916113B-4E8D-435B-829B-6E4449117F76",
"versionEndExcluding": "6.0_u3c",
"versionStartIncluding": "6.0"
},
{
"criteria": "cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3401DF9F-5606-4ABA-A84F-4909405F6955",
"versionEndExcluding": "6.5_u1",
"versionStartIncluding": "6.5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vmware.com"
}