NA

CVE-2023-34060

Published: 14/11/2023 Updated: 21/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . This bypass is not present on port 443 (VCD provider and tenant login). On a new installation of VMware Cloud Director Appliance 10.5, the bypass is not present. VMware Cloud Director Appliance is impacted since it uses an affected version of sssd from the underlying Photon OS. The sssd issue is no longer present in versions of Photon OS that ship with sssd-2.8.1-11 or higher (Photon OS 3) or sssd-2.8.2-9 or higher (Photon OS 4 and 5).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware cloud_director

Exploits

VMware Cloud Director version 105 suffers from an authentication bypass vulnerability ...

Github Repositories

Hi ๐Ÿ‘‹, I'm Abdualhadi Khalifa I am a passionate person and committed to success in development in the fields of technology in general, and information security in particular I have a strong background in this field and different skills that enable me to interact in this field I have worked on many projects in information security And I wrote tools for me to detect vul

Recent Articles

Another month, another bunch of fixes for Microsoft security bugs exploited in the wild
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Plus: VMware closes critical hole, Adobe fixes a whopping 76 flaws

Patch Tuesday Heads up: Microsoft's November Patch Tuesday includes fixes for about 60 vulnerabilities โ€“ including three that have already been found and abused in the wild. First of that trio is CVE-2023-36033: a Windows Desktop Manager (WDM) Core Library elevation-of-privilege vulnerability. This one, an "important" 7.8-of-10-CVSS-rated bug, is not only listed as exploited by miscreants, the method of exploitation also been publicly disclosed.  "An attacker who successfully exploited th...