PT-2023-3750 · Vmware · Vmware Vcenter Server+1

Aleksandar Nikolic

+1

·

Published

2023-06-22

·

Updated

2023-07-13

·

CVE-2023-20896

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions VMware vCenter Server (affected versions not specified)
Description The issue is related to an out-of-bounds read vulnerability in the implementation of the DCERPC protocol in VMware vCenter Server. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet, leading to a denial-of-service of certain services, including vcad, vmdird, and vmafdd.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-04038
CVE-2023-20896

Affected Products

Vmware Vcenter
Vmware Vcenter Server