CISA KEV 정보
| 취약점명 | VMware Tools Authentication Bypass Vulnerability |
|---|---|
| 설명 | VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-287 |
| 등록일 (KEV) | 2023-06-23 |
| 조치 기한 | 2023-07-14 |
| 추가 참고 | https://www.vmware.com/security/advisories/VMSA-2023-0013.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20867 |
NVD 상세 정보
CVSS v3.1: 3.9 LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N설명: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
CWE: CWE-287
참조
- http://www.openwall.com/lists/oss-security/2023/10/16/11 [Mailing List, Patch]
- http://www.openwall.com/lists/oss-security/2023/10/16/2 [Mailing List, Patch]
- https://lists.debian.org/debian-lts-announce/2023/08/msg00020.html [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NVKQ6Y2JFJRWPFOZUOTFO3H27BK5GGOG/ [Mailing List, Release Notes]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJNJMD67QIT6LXLKWSHFM47DCLRSMT6W/ [Mailing List, Release Notes]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZJM6HDRQYS74JA7YNKQBFH2XSZ52HEWH/ [Mailing List, Release Notes]
- https://security.netapp.com/advisory/ntap-20230725-0001/ [Third Party Advisory]
- https://www.debian.org/security/2023/dsa-5493 [Mailing List, Third Party Advisory]
- https://www.vmware.com/security/advisories/VMSA-2023-0013.html [Patch, Vendor Advisory]
- http://www.openwall.com/lists/oss-security/2023/10/16/11 [Mailing List, Patch]
- http://www.openwall.com/lists/oss-security/2023/10/16/2 [Mailing List, Patch]
- https://lists.debian.org/debian-lts-announce/2023/08/msg00020.html [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NVKQ6Y2JFJRWPFOZUOTFO3H27BK5GGOG/ [Mailing List, Release Notes]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJNJMD67QIT6LXLKWSHFM47DCLRSMT6W/ [Mailing List, Release Notes]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZJM6HDRQYS74JA7YNKQBFH2XSZ52HEWH/ [Mailing List, Release Notes]
- ... 외 4건
This product uses the NVD API but is not endorsed or certified by the NVD.