Show filters
121 Total Results
Displaying 21-30 of 121
Sort by:
Attacker Value
Unknown
CVE-2024-22274
Disclosure Date: May 21, 2024 (last updated May 22, 2024)
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
0
Attacker Value
Unknown
CVE-2024-21840
Disclosure Date: January 30, 2024 (last updated February 07, 2024)
Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files.
This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.
0
Attacker Value
Unknown
CVE-2023-43082
Disclosure Date: November 22, 2023 (last updated November 30, 2023)
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.
0
Attacker Value
Unknown
CVE-2023-34056
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
0
Attacker Value
Unknown
CVE-2023-20896
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).
0
Attacker Value
Unknown
CVE-2023-20895
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
0
Attacker Value
Unknown
CVE-2023-20894
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
0
Attacker Value
Unknown
CVE-2023-20893
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
0
Attacker Value
Unknown
CVE-2023-20892
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
0
Attacker Value
Unknown
CVE-2022-37935
Disclosure Date: March 01, 2023 (last updated October 08, 2023)
HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.
0