QID 216291

Date Published: 2022-10-03

QID 216291: VMware ESXi 6.5 Patch Release ESXi670-202206101-SG Missing (VMSA-2022-0016)

VMware ESXi is an enterprise level computer virtualization product.

Affected Versions:
VMware ESXi 6.5.x

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on target.

A malicious actor with administrative access to a virtual machine that has an attached DirectPath I/O (PCI-Passthrough) device can take advantage of a flaw in memory-mapped I/O (MMIO) fill buffers that may leak information stored in physical memory about the hypervisor or other virtual machines that reside on the same ESXi host if the host utilizes Intel processors.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Refer to VMware advisory VMSA-2022-0016 for more information.

    CVEs related to QID 216291

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0016 URL Logo www.vmware.com/security/advisories/VMSA-2022-0016.html