CVE-2023-34056
published 2023-10-25CVE-2023-34056: vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.67%
47.7th percentile
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | 4.0 – 5.5 | — |
| vmware | vmware_cloud_foundation | — | — |
| vmware | vmware_cloud_foundation | — | — |
| vmware | vmware_vcenter_server | >= 7.0 < 7.0U3o | 7.0U3o |
| vmware | vmware_vcenter_server | >= 8.0 < 8.0U2 | 8.0U2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities (CVE-2023-34048, CVE-2023-34056)
vendor_vmware·2023-10-25·CVSS 9.8
CVE-2023-34048 [CRITICAL] VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities (CVE-2023-34048, CVE-2023-34056)
VMSA-2023-0023: VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities (CVE-2023-34048, CVE-2023-34056)
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2023-34048, CVE-2023-34056
Affected products: VMware Cloud Foundation, VMware vCenter Server
GHSA
GHSA-6cr3-pfhw-g3c7: vCenter Server contains a partial information disclosure vulnerability
ghsa_unreviewed·2023-10-25
CVE-2023-34056 [MEDIUM] CWE-922 GHSA-6cr3-pfhw-g3c7: vCenter Server contains a partial information disclosure vulnerability
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
No detection rules found.
No public exploits indexed.
2023-10-25
Published