CVE-2015-2342
Estado: ModificadaAlta (10)—💥 Exploit
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 89%
- Percentil entre todas las CVEs puntuadas: 100
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Módulo de Metasploit (exploit fiable y al alcance de cualquiera) · Java JMX Server Insecure Configuration Java Code Execution
- Publicado en Exploit-DB · Java JMX - Server Insecure Configuration Java Code Execution (Metasploit) (17/2/2015)
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://seclists.org/fulldisclosure/2015/Oct/1
- http://www.securityfocus.com/bid/76930
- http://www.securitytracker.com/id/1033720
- http://www.vmware.com/security/advisories/VMSA-2015-0007.html
- http://www.zerodayinitiative.com/advisories/ZDI-15-455
- https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/
- http://seclists.org/fulldisclosure/2015/Oct/1
- http://www.securityfocus.com/bid/76930
- http://www.securitytracker.com/id/1033720
- http://www.vmware.com/security/advisories/VMSA-2015-0007.html
- http://www.zerodayinitiative.com/advisories/ZDI-15-455
- https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-2342",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-10-12T10:59:01.633",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2015/Oct/1",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/76930",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id/1033720",
"source": "cve@mitre.org"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2015-0007.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-15-455",
"source": "cve@mitre.org"
},
{
"url": "https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2015/Oct/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/76930",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1033720",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2015-0007.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-15-455",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.7elements.co.uk/resources/technical-advisories/cve-2015-2342-vmware-vcenter-remote-code-execution/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol."
},
{
"lang": "es",
"value": "El servicio JMX RMI en Vmware vCenter Server 5.0 en versiones anteriores a u3e, 5.1 en versiones anteriores a u3b, 5.5 en versiones anteriores a u3 y 6.0 en versiones anterioes a u1 no restringe el registro de Mbeans, lo que permite a atacantes remotos ejecutar código arbitrario a través del protocolo RMI."
}
],
"lastModified": "2026-06-17T00:23:57.787",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:vcenter_server:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46C704E0-E165-4A44-A104-6C5B83A83237"
},
{
"criteria": "cpe:2.3:a:vmware:vcenter_server:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0492A2B-EBE2-4303-B8BD-8511D191D1AA"
},
{
"criteria": "cpe:2.3:a:vmware:vcenter_server:5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B12523A-5C1E-408F-BB4B-98EF32C7D676"
},
{
"criteria": "cpe:2.3:a:vmware:vcenter_server:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7499E57A-1F9C-45F0-93F8-F3FB7B0F990F"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "<a href=\"https://cwe.mitre.org/data/definitions/415.html\">CWE-415: Double Free</a>",
"sourceIdentifier": "cve@mitre.org"
}