QID 216269
QID 216269: VMware ESXi 7.0 Patch Release ESXi70U1c-17325551 Missing (VMSA-2020-0029)
VMware ESXi is an enterprise level computer virtualization product.
VMware ESXi contain a denial of service vulnerability due to improper input validation in GuestInfo. VMware has evaluated the severity of this issue to be in the Low severity range with a maximum CVSSv3 base score of 3.3
Affected Versions:
VMware ESXi 7.0 prior to build 17325551
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on target.
A malicious actor with normal user privilege access to a virtual machine can crash the virtual machine's vmx process leading to a denial of service condition.
Solution
Vmware has released patch for VMware ESXi 6.5 , visit VMware ESXi 7.0 Update 1c Release Notes
Refer to VMware advisory VMSA-2020-0029 for more information.
Vendor References
- VMSA-2020-0029 -
www.vmware.com/security/advisories/VMSA-2020-0029.html
CVEs related to QID 216269
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMware ESXi 7.0 Update 1c |
|