Relating to this vendor:
And, this specific program:
VMware vSphere Client 4.x
|brian2600||Secunia PSI 2.0 Not Detecting Older Versions of vSphere Client|
|21st Jun, 2013 00:08|
User Since: 20th Jun, 2013
System Score: N/A
I am experiencing an issue with the Secunia PSI 2.0 and the vSphere Client. Secunia is marking vSphere Client version 220.127.116.11733 as Insecure (which I know). I install the updated version of the vSphere Client 5.x and Secunia marks it the 5.x binary as patched. It doesn't mark the existing 18.104.22.168733 client as insecure or even report on it being installed in the Secunia PSI. Is this a known issue? Why dosen't Secunia Report on the out of date vSphere Client? It seems like its only looking for the latest version and marking it as patched while there are still vulnerable vSphere client version installed on the host.
Any Help is Greatly Appreciated. Thank You
|mogs||RE: Secunia PSI 2.0 Not Detecting Older Versions of vSphere Client|
|21st Jun, 2013 03:50|
User Since: 22nd Apr 2009
System Score: 100%
Last edited on 21st Jun, 2013 07:47
VMWare Sphere Client seems to be detected/reported on an "either/or" basis....as can be seen in the Secunia Advisory here :-http://secunia.com/advisories/48387/
The vulnerability is reported in version 5 and versions prior to 4.1 Update 1.
Update to version 4.1 Update 2 or 5.0 Update 1.
Both products are reported as secure when fully patched, as can be seen here :-
Most Critical Unpatched
There are no unpatched Secunia advisories affecting this product, when all vendor patches are applied..
and here :-
Hope it helps......regards......mogs
Not a customer already?
Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance.