VMware vCenter Server Partial Information Disclosure Vulnerability
CVE-2023-34056
4.3MEDIUM
Key Information
- Vendor
- Vmware
- Status
- Vmware Vcenter Server
- Vmware Cloud Foundation (vmware Vcenter Server)
- Vendor
- CVE Published:
- 25 October 2023
Badges
📰 News Worthy
Summary
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
Affected Version(s)
VMware vCenter Server < 8.0U2
VMware vCenter Server < 7.0U3o
VMware Cloud Foundation (VMware vCenter Server) = 5.x
News Articles
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
First article discovered by Help Net Security
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database1 News Article(s)