CERT-In Vulnerability Note
CIVN-2023-0352
Authentication Bypass Vulnerability in VMware Cloud Director Appliance (VCD Appliance)
Original Issue Date:December 06, 2023
Severity Rating: HIGH
Software Affected
- VMware Cloud Director Appliance versions prior to 10.5.1
Overview
A vulnerability has been reported in the VMware Cloud Director Appliance which could allow a remote attacker to bypass security restrictions on the targeted system.
Description
This vulnerability exists in VMware Cloud Director Appliance due to improper authentication on port 22 (ssh) or port 5480 (appliance management console). A remote attacker can exploit this vulnerability by sending a specially crafted request.
Successful exploitation of this vulnerability which could allow a remote attacker to bypass security restrictions on the targeted system.
Solution
Apply appropriate updates as mentioned
https://www.vmware.com/security/advisories/VMSA-2023-0026.html
Vendor Information
VMware
https://www.vmware.com/security/advisories/VMSA-2023-0026.html
References
https://www.vmware.com/security/advisories/VMSA-2023-0026.html
CVE Name
CVE-2023-34060
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|