VMware vCenter Server Partial Information Disclosure Vulnerability

CVE-2023-34056
4.3MEDIUM

Key Information

Vendor
Vmware
Status
Vmware Vcenter Server
Vmware Cloud Foundation (vmware Vcenter Server)
Vendor
CVE Published:
25 October 2023

Badges

📰 News Worthy

Summary

vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.

Affected Version(s)

VMware vCenter Server < 8.0U2

VMware vCenter Server < 7.0U3o

VMware Cloud Foundation (VMware vCenter Server) = 5.x

News Articles

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • First article discovered by Help Net Security

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database1 News Article(s)
.