QID 216290

Date Published: 2022-07-26

QID 216290: VMware vCenter Server 7.0 Update 7.0 U3F (VMSA-2022-0018)

VMware vCenter Server is a server management solution that helps IT admins manage virtualized hosts and virtual machines in enterprise environments via a single console.

Affected Versions:
VMware vCenter Server Virtual Appliance 7.0 prior to build 20051473

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware vCenter Server with build version using web service present on the target.

A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    VMware has released patch for VMware vCenter Server 7.0,

    Refer to VMware advisory VMSA-2022-0018 for more information.

    CVEs related to QID 216290

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0018 URL Logo www.vmware.com/security/advisories/VMSA-2022-0018.html