VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user’s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.
| Software | From | Fixed in |
|---|---|---|
| vmware / esxi | 6.7-670-201811001 | 6.7-670-201811001.x |
| vmware / vsphere_esxi | 6.7 | 6.7.x |
| vmware / vsphere_esxi | 6.7-update_1 | 6.7-update_1.x |
| vmware / vsphere_esxi | 6.5-a | 6.5-a.x |
| vmware / vsphere_esxi | 6.5-u2 | 6.5-u2.x |
| vmware / vsphere_esxi | 6.5-650-201810002 | 6.5-650-201810002.x |
| vmware / vsphere_esxi | 6.5-650-201811001 | 6.5-650-201811001.x |
| vmware / vsphere_esxi | 6.5-650-201811002 | 6.5-650-201811002.x |
| vmware / vsphere_esxi | 6.5-650-201901001 | 6.5-650-201901001.x |
| vmware / vsphere_esxi | 6.5-650-201903001 | 6.5-650-201903001.x |
| vmware / vsphere_esxi | 6.5-650-201905001 | 6.5-650-201905001.x |
| vmware / vsphere_esxi | 6.5-update_1 | 6.5-update_1.x |
| vmware / vsphere_esxi | 6.5 | 6.5.x |
| vmware / vsphere_esxi | 6.0-beta | 6.0-beta.x |
| vmware / vsphere_esxi | 6.0-600-201810001 | 6.0-600-201810001.x |
| vmware / vsphere_esxi | 6.0-600-201811001 | 6.0-600-201811001.x |
| vmware / vsphere_esxi | 6.0-600-201903001 | 6.0-600-201903001.x |
| vmware / vsphere_esxi | 6.0-600-201905001 | 6.0-600-201905001.x |
| vmware / vsphere_esxi | 6.0-u1a | 6.0-u1a.x |
| vmware / vsphere_esxi | 6.0-u1b | 6.0-u1b.x |
| vmware / vsphere_esxi | 6.0-update_2 | 6.0-update_2.x |
| vmware / vsphere_esxi | 6.0-update_3 | 6.0-update_3.x |
| vmware / vsphere_esxi | 6.0 | 6.0.x |
| vmware / vsphere_esxi | 6.0-u3a | 6.0-u3a.x |
| vmware / vcenter_server | 6.0-u1b | 6.0-u1b.x |
| vmware / vcenter_server | 6.0-a | 6.0-a.x |
| vmware / vcenter_server | 6.0-b | 6.0-b.x |
| vmware / vcenter_server | 6.0-u1 | 6.0-u1.x |
| vmware / vcenter_server | 6.0 | 6.0.x |
| vmware / vcenter_server | 6.0-u3 | 6.0-u3.x |
| vmware / vcenter_server | 6.0-update3d | 6.0-update3d.x |
| vmware / vcenter_server | 6.0-update3e | 6.0-update3e.x |
| vmware / vcenter_server | 6.0-update3f | 6.0-update3f.x |
| vmware / vcenter_server | 6.0-update3g | 6.0-update3g.x |
| vmware / vcenter_server | 6.0-update3h | 6.0-update3h.x |
| vmware / vcenter_server | 6.0-update3i | 6.0-update3i.x |
| vmware / vcenter_server | 6.0-update2 | 6.0-update2.x |
| vmware / vcenter_server | 6.0-update2a | 6.0-update2a.x |
| vmware / vcenter_server | 6.0-update2m | 6.0-update2m.x |
| vmware / vcenter_server | 6.0-update3a | 6.0-update3a.x |
| vmware / vcenter_server | 6.0-update3b | 6.0-update3b.x |
| vmware / vcenter_server | 6.0-update3c | 6.0-update3c.x |
| vmware / vcenter_server | 6.7 | 6.7.x |
| vmware / vcenter_server | 6.7-d | 6.7-d.x |
| vmware / vcenter_server | 6.7-c | 6.7-c.x |
| vmware / vcenter_server | 6.7-b | 6.7-b.x |
| vmware / vcenter_server | 6.7-a | 6.7-a.x |
| vmware / vcenter_server | 6.7-update1 | 6.7-update1.x |
| vmware / vcenter_server | 6.7-update1b | 6.7-update1b.x |
| vmware / vcenter_server | 6.7-update2 | 6.7-update2.x |
| vmware / vcenter_server | 6.7-update2a | 6.7-update2a.x |
| vmware / vcenter_server | 6.7-update2c | 6.7-update2c.x |
| vmware / vcenter_server | 6.5 | 6.5.x |
| vmware / vcenter_server | 6.5-d | 6.5-d.x |
| vmware / vcenter_server | 6.5-c | 6.5-c.x |
| vmware / vcenter_server | 6.5-b | 6.5-b.x |
| vmware / vcenter_server | 6.5-a | 6.5-a.x |
| vmware / vcenter_server | 6.5-update1 | 6.5-update1.x |
| vmware / vcenter_server | 6.5-update1c | 6.5-update1c.x |
| vmware / vcenter_server | 6.5-update1b | 6.5-update1b.x |
| vmware / vcenter_server | 6.5-update1d | 6.5-update1d.x |
| vmware / vcenter_server | 6.5-update1e | 6.5-update1e.x |
| vmware / vcenter_server | 6.5-update1g | 6.5-update1g.x |
| vmware / vcenter_server | 6.5-update2 | 6.5-update2.x |
| vmware / vcenter_server | 6.5-update2b | 6.5-update2b.x |
| vmware / vcenter_server | 6.5-update2c | 6.5-update2c.x |
| vmware / vcenter_server | 6.5-update2d | 6.5-update2d.x |
| vmware / vcenter_server | 6.5-update2g | 6.5-update2g.x |