vCenter Server Partial File Read Vulnerability
CVE-2024-22275
4.9MEDIUM
Key Information
- Vendor
- VMware
- Status
- Vmware Vcenter Server
- Vmware Cloud Foundation (vcenter Server)
- Vendor
- CVE Published:
- 21 May 2024
Badges
👾 Exploit Exists
Summary
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
Affected Version(s)
VMware vCenter Server < 8.0 U2b
VMware vCenter Server < 7.0 U3q
VMware Cloud Foundation (vCenter Server) < 5.1.1
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit exists.
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database0 Proof of Concept(s)