Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rg6m-2r9v-c5fj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

EPSS

Процентиль: 100%
0.94412
Критический

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость модуля Virtual SAN Health Check программного обеспечения для управления гипервизором VMware vSphere Client (HTML5) позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 100%
0.94412
Критический

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-918