Loading HuntDB...

Version 5.0

MAJOR_MINOR 5 CVEs

Known Vulnerabilities

CVE-2024-38815

VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.

MEDIUM CVSS 4.3 Published Oct 09, 2024

CVE-2024-38818

VMware NSX contains a local privilege escalation vulnerability.  An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.

MEDIUM CVSS 6.7 Published Oct 09, 2024

CVE-2024-38817

VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.

MEDIUM CVSS 6.7 Published Oct 09, 2024

CVE-2024-37085

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

MEDIUM CVSS 6.8 Published Jun 25, 2024

CVE-2023-34048

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

CRITICAL CVSS 9.8 Published Oct 25, 2023