PT-2024-4871 · Vmware · Vcenter Server+1

Mal

+1

·

Published

2024-01-08

·

Updated

2025-06-27

·

CVE-2024-22275

CVSS v2.0

6.1

Medium

VectorAV:N/AC:L/Au:M/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: vCenter Server (affected versions not specified)
Description: The issue is related to insufficient protection of internal data in the vCenter Server, which may allow a remote attacker to disclose sensitive information. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-05395
CVE-2024-22275

Affected Products

Vmware Vcenter
Vcenter Server