<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – VMware vCenter Server (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/vcenter.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/vcenter-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – VMware vCenter Server (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:00 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-41250 – VMware vCenter contains an SMTP header injection vulnerability. A malicious acto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41250</guid>
    <pubDate>Mon, 29 Sep 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41250</strong></p>
  <p>VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41246 – VMware Tools for Windows contains an improper authorisation vulnerability due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41246</guid>
    <pubDate>Mon, 29 Sep 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41246</strong></p>
  <p>VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-37101 – A potential security vulnerability has been identified in HPE OneView for VMware...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-37101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-37101</guid>
    <pubDate>Thu, 26 Jun 2025 06:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-37101</strong></p>
  <p>A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-37101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41225 – The vCenter Server contains an authenticated command-execution vulnerability. A ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41225</guid>
    <pubDate>Tue, 20 May 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41225</strong></p>
  <p>The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2241 – A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2241</guid>
    <pubDate>Mon, 17 Mar 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2241</strong></p>
  <p>A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can le…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38813 – The vCenter Server contains a privilege escalation vulnerability. A malicious ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38813</guid>
    <pubDate>Tue, 17 Sep 2024 18:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38813</strong></p>
  <p>The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38812 – The vCenter Server contains a heap-overflow vulnerability in the implementation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38812</guid>
    <pubDate>Tue, 17 Sep 2024 18:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38812</strong></p>
  <p>The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37081 – The vCenter Server contains multiple local privilege escalation vulnerabilities ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37081</guid>
    <pubDate>Tue, 18 Jun 2024 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37081</strong></p>
  <p>The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-556</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37080 – vCenter Server contains a heap-overflow vulnerability in the implementation of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37080</guid>
    <pubDate>Tue, 18 Jun 2024 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37080</strong></p>
  <p>vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37079 – vCenter Server contains a heap-overflow vulnerability in the implementation of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37079</guid>
    <pubDate>Tue, 18 Jun 2024 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37079</strong></p>
  <p>vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22274 – The vCenter Server contains an authenticated remote code execution vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22274</guid>
    <pubDate>Tue, 21 May 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22274</strong></p>
  <p>The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21840 – Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21840</guid>
    <pubDate>Tue, 30 Jan 2024 03:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21840</strong></p>
  <p>Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files.  This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43082 – Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43082</guid>
    <pubDate>Wed, 22 Nov 2023 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43082</strong></p>
  <p>Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-34048 – vCenter Server contains an out-of-bounds write vulnerability in the implementati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34048</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34048</strong></p>
  <p>vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20895 – The VMware vCenter Server contains a memory corruption vulnerability in the impl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20895</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20895</strong></p>
  <p>The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20894 – The VMware vCenter Server contains an out-of-bounds write vulnerability in the i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20894</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20894</strong></p>
  <p>The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20893 – The VMware vCenter Server contains a use-after-free vulnerability in the impleme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20893</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20893</strong></p>
  <p>The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20892 – The vCenter Server contains a heap overflow vulnerability due to the usage of un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20892</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20892</strong></p>
  <p>The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4441 – Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4441</guid>
    <pubDate>Tue, 31 Jan 2023 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4441</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 04.9.1.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31680 – The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31680</guid>
    <pubDate>Fri, 07 Oct 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31680</strong></p>
  <p>The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22982 – The vCenter Server contains a server-side request forgery (SSRF) vulnerability. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22982</guid>
    <pubDate>Wed, 13 Jul 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22982</strong></p>
  <p>The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22049 – The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forger...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22049</guid>
    <pubDate>Wed, 24 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22049</strong></p>
  <p>The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21980 – The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21980</guid>
    <pubDate>Wed, 24 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21980</strong></p>
  <p>The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22048 – The vCenter Server contains a privilege escalation vulnerability in the IWA (Int...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22048</guid>
    <pubDate>Wed, 10 Nov 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22048</strong></p>
  <p>The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22019 – The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22019</guid>
    <pubDate>Thu, 23 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22019</strong></p>
  <p>The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial of service condition.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22015 – The vCenter Server contains multiple local privilege escalation vulnerabilities ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22015</guid>
    <pubDate>Thu, 23 Sep 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22015</strong></p>
  <p>The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22014 – The vCenter Server contains an authenticated code execution vulnerability in VAM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22014</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22014</strong></p>
  <p>The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22013 – The vCenter Server contains a file path traversal vulnerability leading to infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22013</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22013</strong></p>
  <p>The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22012 – The vCenter Server contains an information disclosure vulnerability due to an un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22012</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22012</strong></p>
  <p>The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22010 – The vCenter Server contains a denial-of-service vulnerability in VPXD service. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22010</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22010</strong></p>
  <p>The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create a denial of service condition due to excessive memory consumption by VPXD service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22009 – The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22009</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22009</strong></p>
  <p>The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory consumption by VAPI service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22008 – The vCenter Server contains an information disclosure vulnerability in VAPI (vCe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22008</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22008</strong></p>
  <p>The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22006 – The vCenter Server contains a reverse proxy bypass vulnerability due to the way ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22006</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22006</strong></p>
  <p>The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22005 – The vCenter Server contains an arbitrary file upload vulnerability in the Analyt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22005</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22005</strong></p>
  <p>The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21991 – The vCenter Server contains a local privilege escalation vulnerability due to th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21991</guid>
    <pubDate>Wed, 22 Sep 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21991</strong></p>
  <p>The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21986 – The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21986</guid>
    <pubDate>Wed, 26 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21986</strong></p>
  <p>The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21985 – The vSphere Client (HTML5) contains a remote code execution vulnerability due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21985</guid>
    <pubDate>Wed, 26 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21985</strong></p>
  <p>The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-26987 – Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26987</guid>
    <pubDate>Mon, 15 Mar 2021 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-26987</strong></p>
  <p>Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12.2 contain vulnerable versions of SpringB…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21972 – The vSphere Client (HTML5) contains a remote code execution vulnerability in a v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21972</guid>
    <pubDate>Wed, 24 Feb 2021 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21972</strong></p>
  <p>The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Clo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3994 – VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3994</guid>
    <pubDate>Tue, 20 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3994</strong></p>
  <p>VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3952 – Under certain conditions, vmdir that ships with VMware vCenter Server, as part o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3952</guid>
    <pubDate>Fri, 10 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3952</strong></p>
  <p>Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5534 – VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5534</guid>
    <pubDate>Wed, 18 Sep 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5534</strong></p>
  <p>VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig properties. A malicious actor with access to query the vAppConfig properties of a virtual machine deployed from an OVF may be able to view the cre…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5532 – VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5532</guid>
    <pubDate>Wed, 18 Sep 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5532</strong></p>
  <p>VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to d…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6179 – An XML External Entity (XXE) processing vulnerability was reported in Lenovo XCl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6179</guid>
    <pubDate>Tue, 03 Sep 2019 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6179</strong></p>
  <p>An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11242 – A man-in-the-middle vulnerability related to vCenter access was found in Cohesit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11242</guid>
    <pubDate>Fri, 12 Jul 2019 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11242</strong></p>
  <p>A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. This vulnerability could expose Cohesity user credentials configured to access vCenter.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5492 – Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5492</guid>
    <pubDate>Mon, 29 Apr 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5492</strong></p>
  <p>Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3709 – IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3709</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3709</strong></p>
  <p>IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1223 – Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may le...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1223</guid>
    <pubDate>Mon, 17 Sep 2018 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1223</strong></p>
  <p>Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-5761 – A man-in-the-middle vulnerability related to vCenter access was found in Rubrik ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5761</guid>
    <pubDate>Mon, 22 Jan 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-5761</strong></p>
  <p>A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4943 – VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4943</guid>
    <pubDate>Wed, 20 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4943</strong></p>
  <p>VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4927 – VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4927</guid>
    <pubDate>Fri, 17 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4927</strong></p>
  <p>VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1378 – IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed une...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1378</guid>
    <pubDate>Thu, 05 Oct 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1378</strong></p>
  <p>IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4923 – VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4923</guid>
    <pubDate>Tue, 01 Aug 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4923</strong></p>
  <p>VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4921 – VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4921</guid>
    <pubDate>Tue, 01 Aug 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4921</strong></p>
  <p>VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4919 – VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4919</guid>
    <pubDate>Fri, 28 Jul 2017 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4919</strong></p>
  <p>VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4917 – VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4917</guid>
    <pubDate>Wed, 07 Jun 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4917</strong></p>
  <p>VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4057 – The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4057</guid>
    <pubDate>Tue, 21 Feb 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4057</strong></p>
  <p>The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings screen, which allows remote attackers to discover the admin user password by sniffing the network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-7460 – The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7460</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-7460</strong></p>
  <p>The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-7459 – VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7459</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-7459</strong></p>
  <p>VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-2076 – Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2076</guid>
    <pubDate>Fri, 15 Apr 2016 14:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-2076</strong></p>
  <p>Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-6934 – Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orches...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6934</guid>
    <pubDate>Mon, 21 Dec 2015 03:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-6934</strong></p>
  <p>Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-2342 – The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2342</guid>
    <pubDate>Mon, 12 Oct 2015 10:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-2342</strong></p>
  <p>The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-3790 – Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3790</guid>
    <pubDate>Sun, 01 Jun 2014 04:29:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-3790</strong></p>
  <p>Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3520 – VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3520</guid>
    <pubDate>Mon, 17 Jun 2013 03:29:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3520</strong></p>
  <p>VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-3080 – VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3080</guid>
    <pubDate>Wed, 01 May 2013 12:00:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-3080</strong></p>
  <p>VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cause a denial of service, by leveraging Virtual Appliance Management Interface (VAMI) web-interface access.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-3079 – VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3079</guid>
    <pubDate>Wed, 01 May 2013 12:00:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-3079</strong></p>
  <p>VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-1659 – VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1659</guid>
    <pubDate>Fri, 22 Feb 2013 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-1659</strong></p>
  <p>VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-6326 – VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6326</guid>
    <pubDate>Fri, 22 Feb 2013 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-6326</strong></p>
  <p>VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1405 – VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware Virt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1405</guid>
    <pubDate>Fri, 15 Feb 2013 12:09:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1405</strong></p>
  <p>VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memo…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1405">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
