10

CVE-2020-3992

Warnung

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareCloud Foundation Version >= 3.0 < 3.10.1.2
VMwareCloud Foundation Version >= 4.0 < 4.1.0.1
VMwareESXi Version6.5 Update-
VMwareESXi Version6.5 Update2
VMwareESXi Version6.5 Update650-201701001
VMwareESXi Version6.5 Update650-201703001
VMwareESXi Version6.5 Update650-201703002
VMwareESXi Version6.5 Update650-201704001
VMwareESXi Version6.5 Update650-201707101
VMwareESXi Version6.5 Update650-201707102
VMwareESXi Version6.5 Update650-201707103
VMwareESXi Version6.5 Update650-201707201
VMwareESXi Version6.5 Update650-201707202
VMwareESXi Version6.5 Update650-201707203
VMwareESXi Version6.5 Update650-201707204
VMwareESXi Version6.5 Update650-201707205
VMwareESXi Version6.5 Update650-201707206
VMwareESXi Version6.5 Update650-201707207
VMwareESXi Version6.5 Update650-201707208
VMwareESXi Version6.5 Update650-201707209
VMwareESXi Version6.5 Update650-201707210
VMwareESXi Version6.5 Update650-201707211
VMwareESXi Version6.5 Update650-201707212
VMwareESXi Version6.5 Update650-201707213
VMwareESXi Version6.5 Update650-201707214
VMwareESXi Version6.5 Update650-201707215
VMwareESXi Version6.5 Update650-201707216
VMwareESXi Version6.5 Update650-201707217
VMwareESXi Version6.5 Update650-201707218
VMwareESXi Version6.5 Update650-201707219
VMwareESXi Version6.5 Update650-201707220
VMwareESXi Version6.5 Update650-201707221
VMwareESXi Version6.5 Update650-201710001
VMwareESXi Version6.5 Update650-201712001
VMwareESXi Version6.5 Update650-201803001
VMwareESXi Version6.5 Update650-201806001
VMwareESXi Version6.5 Update650-201808001
VMwareESXi Version6.5 Update650-201810001
VMwareESXi Version6.5 Update650-201810002
VMwareESXi Version6.5 Update650-201811001
VMwareESXi Version6.5 Update650-201811002
VMwareESXi Version6.5 Update650-201811301
VMwareESXi Version6.5 Update650-201901001
VMwareESXi Version6.5 Update650-201903001
VMwareESXi Version6.5 Update650-201905001
VMwareESXi Version6.5 Update650-201908001
VMwareESXi Version6.5 Update650-201910001
VMwareESXi Version6.5 Update650-20191004001
VMwareESXi Version6.5 Update650-201911001
VMwareESXi Version6.5 Update650-201911401
VMwareESXi Version6.5 Update650-201911402
VMwareESXi Version6.5 Update650-201912001
VMwareESXi Version6.5 Update650-201912002
VMwareESXi Version6.5 Update650-201912101
VMwareESXi Version6.5 Update650-201912102
VMwareESXi Version6.5 Update650-201912103
VMwareESXi Version6.5 Update650-201912104
VMwareESXi Version6.5 Update650-201912301
VMwareESXi Version6.5 Update650-201912401
VMwareESXi Version6.5 Update650-201912402
VMwareESXi Version6.5 Update650-201912403
VMwareESXi Version6.5 Update650-201912404
VMwareESXi Version6.5 Update650-202005001
VMwareESXi Version6.5 Update650-202006001
VMwareESXi Version6.5 Update650-202007001
VMwareESXi Version6.5 Update650-202010001
VMwareESXi Version6.7 Update-
VMwareESXi Version6.7 Update670-201806001
VMwareESXi Version6.7 Update670-201807001
VMwareESXi Version6.7 Update670-201808001
VMwareESXi Version6.7 Update670-201810001
VMwareESXi Version6.7 Update670-201810101
VMwareESXi Version6.7 Update670-201810102
VMwareESXi Version6.7 Update670-201810103
VMwareESXi Version6.7 Update670-201810201
VMwareESXi Version6.7 Update670-201810202
VMwareESXi Version6.7 Update670-201810203
VMwareESXi Version6.7 Update670-201810204
VMwareESXi Version6.7 Update670-201810205
VMwareESXi Version6.7 Update670-201810206
VMwareESXi Version6.7 Update670-201810207
VMwareESXi Version6.7 Update670-201810208
VMwareESXi Version6.7 Update670-201810209
VMwareESXi Version6.7 Update670-201810210
VMwareESXi Version6.7 Update670-201810211
VMwareESXi Version6.7 Update670-201810212
VMwareESXi Version6.7 Update670-201810213
VMwareESXi Version6.7 Update670-201810214
VMwareESXi Version6.7 Update670-201810215
VMwareESXi Version6.7 Update670-201810216
VMwareESXi Version6.7 Update670-201810217
VMwareESXi Version6.7 Update670-201810218
VMwareESXi Version6.7 Update670-201810219
VMwareESXi Version6.7 Update670-201810220
VMwareESXi Version6.7 Update670-201810221
VMwareESXi Version6.7 Update670-201810222
VMwareESXi Version6.7 Update670-201810223
VMwareESXi Version6.7 Update670-201810224
VMwareESXi Version6.7 Update670-201810225
VMwareESXi Version6.7 Update670-201810226
VMwareESXi Version6.7 Update670-201810227
VMwareESXi Version6.7 Update670-201810228
VMwareESXi Version6.7 Update670-201810229
VMwareESXi Version6.7 Update670-201810230
VMwareESXi Version6.7 Update670-201810231
VMwareESXi Version6.7 Update670-201810232
VMwareESXi Version6.7 Update670-201810233
VMwareESXi Version6.7 Update670-201810234
VMwareESXi Version6.7 Update670-201811001
VMwareESXi Version6.7 Update670-201901001
VMwareESXi Version6.7 Update670-201901401
VMwareESXi Version6.7 Update670-201901402
VMwareESXi Version6.7 Update670-201901403
VMwareESXi Version6.7 Update670-201903001
VMwareESXi Version6.7 Update670-201904001
VMwareESXi Version6.7 Update670-201904201
VMwareESXi Version6.7 Update670-201904201-ug
VMwareESXi Version6.7 Update670-201904202
VMwareESXi Version6.7 Update670-201904202-ug
VMwareESXi Version6.7 Update670-201904203
VMwareESXi Version6.7 Update670-201904203-ug
VMwareESXi Version6.7 Update670-201904204
VMwareESXi Version6.7 Update670-201904204-ug
VMwareESXi Version6.7 Update670-201904205
VMwareESXi Version6.7 Update670-201904205-ug
VMwareESXi Version6.7 Update670-201904206
VMwareESXi Version6.7 Update670-201904206-ug
VMwareESXi Version6.7 Update670-201904207
VMwareESXi Version6.7 Update670-201904207-ug
VMwareESXi Version6.7 Update670-201904208
VMwareESXi Version6.7 Update670-201904208-ug
VMwareESXi Version6.7 Update670-201904209
VMwareESXi Version6.7 Update670-201904209-ug
VMwareESXi Version6.7 Update670-201904210
VMwareESXi Version6.7 Update670-201904210-ug
VMwareESXi Version6.7 Update670-201904211
VMwareESXi Version6.7 Update670-201904211-ug
VMwareESXi Version6.7 Update670-201904212
VMwareESXi Version6.7 Update670-201904212-ug
VMwareESXi Version6.7 Update670-201904213
VMwareESXi Version6.7 Update670-201904213-ug
VMwareESXi Version6.7 Update670-201904214
VMwareESXi Version6.7 Update670-201904214-ug
VMwareESXi Version6.7 Update670-201904215
VMwareESXi Version6.7 Update670-201904215-ug
VMwareESXi Version6.7 Update670-201904216
VMwareESXi Version6.7 Update670-201904216-ug
VMwareESXi Version6.7 Update670-201904217
VMwareESXi Version6.7 Update670-201904217-ug
VMwareESXi Version6.7 Update670-201904218
VMwareESXi Version6.7 Update670-201904218-ug
VMwareESXi Version6.7 Update670-201904219
VMwareESXi Version6.7 Update670-201904219-ug
VMwareESXi Version6.7 Update670-201904220
VMwareESXi Version6.7 Update670-201904220-ug
VMwareESXi Version6.7 Update670-201904221
VMwareESXi Version6.7 Update670-201904221-ug
VMwareESXi Version6.7 Update670-201904222
VMwareESXi Version6.7 Update670-201904222-ug
VMwareESXi Version6.7 Update670-201904223
VMwareESXi Version6.7 Update670-201904223-ug
VMwareESXi Version6.7 Update670-201904224
VMwareESXi Version6.7 Update670-201904224-ug
VMwareESXi Version6.7 Update670-201904225
VMwareESXi Version6.7 Update670-201904225-ug
VMwareESXi Version6.7 Update670-201904226
VMwareESXi Version6.7 Update670-201904226-ug
VMwareESXi Version6.7 Update670-201904227
VMwareESXi Version6.7 Update670-201904227-ug
VMwareESXi Version6.7 Update670-201904228
VMwareESXi Version6.7 Update670-201904228-ug
VMwareESXi Version6.7 Update670-201904229
VMwareESXi Version6.7 Update670-201904229-ug
VMwareESXi Version6.7 Update670-201905001
VMwareESXi Version6.7 Update670-201906002
VMwareESXi Version6.7 Update670-201908101
VMwareESXi Version6.7 Update670-201908102
VMwareESXi Version6.7 Update670-201908103
VMwareESXi Version6.7 Update670-201908104
VMwareESXi Version6.7 Update670-201908201
VMwareESXi Version6.7 Update670-201908202
VMwareESXi Version6.7 Update670-201908203
VMwareESXi Version6.7 Update670-201908204
VMwareESXi Version6.7 Update670-201908205
VMwareESXi Version6.7 Update670-201908206
VMwareESXi Version6.7 Update670-201908207
VMwareESXi Version6.7 Update670-201908208
VMwareESXi Version6.7 Update670-201908209
VMwareESXi Version6.7 Update670-201908210
VMwareESXi Version6.7 Update670-201908211
VMwareESXi Version6.7 Update670-201908212
VMwareESXi Version6.7 Update670-201908213
VMwareESXi Version6.7 Update670-201908214
VMwareESXi Version6.7 Update670-201908215
VMwareESXi Version6.7 Update670-201908216
VMwareESXi Version6.7 Update670-201908217
VMwareESXi Version6.7 Update670-201908218
VMwareESXi Version6.7 Update670-201908219
VMwareESXi Version6.7 Update670-201908220
VMwareESXi Version6.7 Update670-201908221
VMwareESXi Version6.7 Update670-201912001
VMwareESXi Version6.7 Update670-201912101
VMwareESXi Version6.7 Update670-201912102
VMwareESXi Version6.7 Update670-201912401
VMwareESXi Version6.7 Update670-201912402
VMwareESXi Version6.7 Update670-201912403
VMwareESXi Version6.7 Update670-201912404
VMwareESXi Version6.7 Update670-201912405
VMwareESXi Version6.7 Update670-202004001
VMwareESXi Version6.7 Update670-202004002
VMwareESXi Version6.7 Update670-202004301
VMwareESXi Version6.7 Update670-202004401
VMwareESXi Version6.7 Update670-202004402
VMwareESXi Version6.7 Update670-202004403
VMwareESXi Version6.7 Update670-202004404
VMwareESXi Version6.7 Update670-202004405
VMwareESXi Version6.7 Update670-202004406
VMwareESXi Version6.7 Update670-202004407
VMwareESXi Version6.7 Update670-202004408
VMwareESXi Version6.7 Update670-202006001
VMwareESXi Version6.7 Update670-202008001
VMwareESXi Version6.7 Update670-202010001
VMwareESXi Version7.0.0 Update-
VMwareESXi Version7.0.0 Update1.20.16321839

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

VMware ESXi OpenSLP Use-After-Free Vulnerability

Schwachstelle

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 90.42% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.