QID 216294

Date Published: 2022-09-20

QID 216294: VMware ESXi 6.5 Patch Release ESXi650-202207401-SG Missing (VMSA-2022-0020)

VMware ESXi is an enterprise level computer virtualization product.

Affected Versions:
VMware ESXi 6.5.x prior build 19997716

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on target.

A malicious actor with administrative access to a virtual machine can take advantage of various side-channel CPU flaws that may leak information stored in physical memory about the hypervisor or other virtual machines that reside on the same ESXi host.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Refer to VMware advisory VMSA-2022-0020 for more information.

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0020 URL Logo www.vmware.com/security/advisories/VMSA-2022-0020.html