Show filters
121 Total Results
Displaying 11-20 of 121
Sort by:
Attacker Value
Unknown

CVE-2022-31697

Disclosure Date: December 13, 2022 (last updated October 08, 2023)
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
Attacker Value
Unknown

CVE-2021-22006

Disclosure Date: September 23, 2021 (last updated October 07, 2023)
The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.
Attacker Value
Unknown

CVE-2024-38812

Disclosure Date: September 17, 2024 (last updated October 03, 2024)
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Attacker Value
Unknown

CVE-2021-21986

Disclosure Date: May 26, 2021 (last updated October 07, 2023)
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.
Attacker Value
Unknown

CVE-2024-38813

Disclosure Date: September 17, 2024 (last updated October 03, 2024)
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
Attacker Value
Unknown

CVE-2024-37087

Disclosure Date: June 25, 2024 (last updated June 26, 2024)
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
0
Attacker Value
Unknown

CVE-2024-22385

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.
0
Attacker Value
Unknown

CVE-2024-37081

Disclosure Date: June 18, 2024 (last updated June 18, 2024)
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
0
Attacker Value
Unknown

CVE-2024-37080

Disclosure Date: June 18, 2024 (last updated August 31, 2024)
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Attacker Value
Unknown

CVE-2024-22275

Disclosure Date: May 21, 2024 (last updated May 22, 2024)
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
0