CVE-2024-22275
- EPSS 0.99%
- Veröffentlicht 21.05.2024 18:15:09
- Zuletzt bearbeitet 27.06.2025 13:38:06
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
CVE-2024-22274
- EPSS 2.51%
- Veröffentlicht 21.05.2024 18:15:09
- Zuletzt bearbeitet 27.06.2025 13:37:52
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
CVE-2023-34056
- EPSS 0.67%
- Veröffentlicht 25.10.2023 18:17:27
- Zuletzt bearbeitet 21.11.2024 08:06:29
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
CVE-2023-34048
- EPSS 99.43%
- Veröffentlicht 25.10.2023 18:17:27
- Zuletzt bearbeitet 30.10.2025 19:52:27
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
CVE-2023-20896
- EPSS 0.91%
- Veröffentlicht 22.06.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:41:46
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leadi...
CVE-2023-20895
- EPSS 1.38%
- Veröffentlicht 22.06.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 07:41:46
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
CVE-2023-20894
- EPSS 33.95%
- Veröffentlicht 22.06.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 07:41:46
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet lead...
CVE-2023-20893
- EPSS 1.25%
- Veröffentlicht 22.06.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 07:41:46
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating syste...
CVE-2023-20892
- EPSS 1.85%
- Veröffentlicht 22.06.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 07:41:46
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execut...
CVE-2022-31697
- EPSS 0.13%
- Veröffentlicht 13.12.2022 16:15:19
- Zuletzt bearbeitet 22.04.2025 16:15:29
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore)...