CERT-In Vulnerability Note
CIVN-2023-0326
Multiple Vulnerabilities in VMware vCenter Server
Original Issue Date:October 25, 2023
Severity Rating: CRITICAL
Software Affected
- VMware vCenter Server versions 7.0 & 8.0
- VMware Cloud Foundation (vCenter Server) versions 4.x & 5.x
Overview
Multiple vulnerabilities have been reported VMware vCenter Server which could allow remote attackers to execute arbitrary code and obtain sensitive information on the targeted system.
Description
1. Out-of-Bounds Write Vulnerability
(
CVE-2023-34048
)
This vulnerability exists in the VMware vCenter Server due to flaw in out-of-bounds write. A remote attacker could exploit this vulnerability by sending a specially crafted request. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the target system.
2. Information Disclosure Vulnerability
(
CVE-2023-34056
)
This vulnerability exists in the VMware vCenter Server due to improper authorization validation. A remote attacker could exploit this vulnerability by sending a specially crafted request. Successful exploitation of this vulnerability could allow a remote authenticated attacker could exploit this vulnerability to obtain sensitive information from the target system.
Solution
Upgrade to the latest versions as mentioned by the vendor
https://www.vmware.com/security/advisories/VMSA-2023-0023.html
Vendor Information
VMWare
https://www.vmware.com/security/advisories/VMSA-2023-0023.html
References
https://www.vmware.com/security/advisories/VMSA-2023-0023.html
CVE Name
CVE-2023-34048
CVE-2023-34056
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|