VMware vCenter Server Partial Information Disclosure Vulnerability
CVE-2023-34056

4.3MEDIUM

Key Information:

Badges

πŸ“° News Worthy

Summary

vCenter Server contains a partial information disclosure vulnerability.Β A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.

Affected Version(s)

VMware Cloud Foundation (VMware vCenter Server) Linux 5.x

VMware Cloud Foundation (VMware vCenter Server) Linux 4.x

VMware vCenter Server Linux 8.0 < 8.0U2

News Articles

VMware patches critical vulnerability in vCenter Server (CVE-2023-34048) - Help Net Security

VMware has fixed a critical out-of-bounds write vulnerability (CVE-2023-34048) in vCenter Server, its popular server management software.

1 year ago

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“°

    First article discovered by Help Net Security

  • Vulnerability published

  • Vulnerability Reserved

.