VMware

Cloud Foundation

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.26%
  • Veröffentlicht 20.05.2025 14:24:24
  • Zuletzt bearbeitet 15.04.2026 00:35:42

VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to cre...

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 20.05.2025 14:24:17
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.

Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 20.05.2025 13:15:48
  • Zuletzt bearbeitet 12.06.2025 16:22:47

VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.

Medienbericht
  • EPSS 0.42%
  • Veröffentlicht 20.05.2025 13:15:47
  • Zuletzt bearbeitet 15.04.2026 00:35:42

VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to gain access to sensitive information.

Medienbericht
  • EPSS 0.66%
  • Veröffentlicht 20.05.2025 13:15:47
  • Zuletzt bearbeitet 15.04.2026 00:35:42

VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.

Medienbericht
  • EPSS 0.34%
  • Veröffentlicht 13.05.2025 05:08:03
  • Zuletzt bearbeitet 11.07.2025 14:27:30

VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a mali...

  • EPSS 1.16%
  • Veröffentlicht 13.07.2021 19:15:09
  • Zuletzt bearbeitet 31.10.2025 11:44:38

SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.

  • EPSS 0.96%
  • Veröffentlicht 13.07.2021 19:15:09
  • Zuletzt bearbeitet 31.10.2025 11:44:38

OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-...