Vmware Vcenter Server vulnerabilities
81 known vulnerabilities affecting vmware/vcenter_server.
Total CVEs
81
CISA KEV
11
actively exploited
Public exploits
15
Exploited in wild
13
Severity breakdown
CRITICAL20HIGH29MEDIUM31LOW1
Vulnerabilities
Page 1 of 5
CVE-2021-22005P1CRITICALCVSS 9.8KEVPoCRansomwarev6.5v6.7+1 more2021-09-23
CVE-2021-22005 [CRITICAL] CWE-22 CVE-2021-22005: The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malic
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
nvd
CVE-2021-21985P1CRITICALCVSS 9.8KEVPoCRansomwarev6.5v6.7+1 more2021-05-26
CVE-2021-21985 [CRITICAL] CWE-918 CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input valid
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system
nvd
CVE-2021-21972P1CRITICALCVSS 9.8KEVPoCRansomwarev6.5v6.7+1 more2021-02-24
CVE-2021-21972 [CRITICAL] CWE-22 CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 befo
nvd
CVE-2023-34048P1CRITICALCVSS 9.8KEVPoC≥ 4.0, ≤ 5.5v7.0+1 more2023-10-25
CVE-2023-34048 [CRITICAL] CWE-787 CVE-2023-34048: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC pro
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
nvd
CVE-2020-3952P1CRITICALCVSS 9.8KEVPoCv6.72020-04-10
CVE-2020-3952 [CRITICAL] CWE-306 CVE-2020-3952: Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or ext
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
nvd
CVE-2021-21973P1MEDIUMCVSS 5.3KEVPoCv6.5v6.7+1 more2021-02-24
CVE-2021-21973 [MEDIUM] CWE-918 CVE-2021-21973: The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to impro
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x
nvd
CVE-2021-22017P1MEDIUMCVSS 5.3KEVPoCv6.72021-09-23
CVE-2021-22017 [MEDIUM] CVE-2021-22017: Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI n
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.
nvd
CVE-2024-38812P1CRITICALCVSS 9.8KEVv7.0v8.02024-09-17
CVE-2024-38812 [CRITICAL] CWE-122 CVE-2024-38812: The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protoc
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2022-22948P2MEDIUMCVSS 6.5KEVPoCv6.5v6.7+1 more2022-03-29
CVE-2022-22948 [MEDIUM] CWE-276 CVE-2022-22948: The vCenter Server contains an information disclosure vulnerability due to improper permission of fi
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
nvd
CVE-2024-37079P1CRITICALCVSS 9.8KEVv8.0v7.02024-06-18
CVE-2024-37079 [CRITICAL] CWE-787 CVE-2024-37079: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2024-38813P1CRITICALCVSS 9.8KEVv7.0v8.02024-09-17
CVE-2024-38813 [CRITICAL] CWE-250 CVE-2024-38813: The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network acc
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
nvd
CVE-2021-21980P2HIGHCVSS 7.5ExploitedPoCv6.5v6.72021-11-24
CVE-2021-21980 [HIGH] CVE-2021-21980: The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A ma
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
nvd
CVE-2009-2698P2HIGHCVSS 7.8ExploitedPoCv4.02009-08-27
CVE-2009-2698 [HIGH] CWE-476 CVE-2009-2698: The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in t
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.
nvd
CVE-2015-2342P2CRITICALCVSS 10.0PoCv5.0v5.1+2 more2015-10-12
CVE-2015-2342 [CRITICAL] CVE-2015-2342: The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.
nvd
CVE-2023-20894P2CRITICALCVSS 9.8fixed in 7.0v7.0+1 more2023-06-22
CVE-2023-20894 [CRITICAL] CWE-787 CVE-2023-20894: The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
nvd
CVE-2024-37081P3HIGHCVSS 7.8PoCv8.0v7.02024-06-18
CVE-2024-37081 [HIGH] CWE-556 CVE-2024-37081: The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfigurat
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
nvd
CVE-2024-37080P2CRITICALCVSS 9.8v8.0v7.02024-06-18
CVE-2024-37080 [CRITICAL] CWE-787 CVE-2024-37080: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2022-31680P2CRITICALCVSS 9.1fixed in 6.5v6.52022-10-07
CVE-2022-31680 [CRITICAL] CWE-502 CVE-2022-31680: The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services co
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.
nvd
CVE-2021-21986P2CRITICALCVSS 9.8v6.5v6.7+1 more2021-05-26
CVE-2021-21986 [CRITICAL] CWE-306 CVE-2021-21986: The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Vi
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authe
nvd
CVE-2021-22015P3HIGHCVSS 7.8PoCv6.5v6.7+1 more2021-09-23
CVE-2021-22015 [HIGH] CWE-552 CVE-2021-22015: The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper perm
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.
nvd
1 / 5Next →