QID 216262
Date Published: 2021-08-03
QID 216262: VMware ESXi 6.7 Patch Release ESXi670-202103101-SG Missing (VMSA-2021-0014)
VMware ESXi is an enterprise level computer virtualization product.
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability.
Affected Versions:
VMware ESXi 6.7 prior to build 17700523
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on target.
QID Detection Logic (Authenticated):
This QID checks whether slpd service is off as mentioned in the workaround. If sfcbd service is off, QID will not flag.
A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
Refer to VMware advisory VMSA-2021-0014 for more information.
Workaround:
Disable the SFCB service (CIM Server) on the ESX/ESXi host
Please visit here for more information.
- VMSA-2021-0014 -
www.vmware.com/security/advisories/VMSA-2021-0014.html
CVEs related to QID 216262
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2021-0014 |
|