2.7
CVE-2026-41709
- EPSS 0.38%
- Veröffentlicht 30.07.2026 12:45:02
- Zuletzt bearbeitet 30.07.2026 19:07:59
- CVE-Watchlists
- Unerledigt
ESX insufficient logging vulnerability
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerVMware
≫
Produkt
Cloud Foundation
Default Statusunaffected
Version
9.1.x.x
Status
affected
Version
9.0.x.x
Status
affected
Version
5.x
Version <
5.2.4
Status
affected
HerstellerVMware
≫
Produkt
vSphere Foundation
Default Statusunaffected
Version
9.1.x.x
Status
affected
Version
9.0.x.x
Status
affected
HerstellerVMware
≫
Produkt
ESX
Default Statusunaffected
Version
9.1.x.x
Version <
ESXi-9.1.0.0-25370933
Status
affected
Version
9.0.x.x
Version <
ESXi-9.0.2.0100-25595025
Status
affected
Version
8.0
Version <
ESXi80U3j-25429389
Status
affected
HerstellerVMware
≫
Produkt
Telco Cloud Platform
Default Statusunaffected
Version
5.1.x
Status
affected
Version
5.0.x
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.309 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 2.7 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
|
CWE-778 Insufficient Logging
When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017