QID 216306
Date Published: 2023-02-21
QID 216306: VMware vCenter Server 6.7 Update 6.7 U3S (VMSA-2022-0030)
VMware vCenter Server is a server management solution that helps IT admins manage virtualized hosts and virtual machines in enterprise environments via a single console.
Affected Versions:
VMware vCenter Server Virtual Appliance 6.7 prior to build 20504362
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware vCenter Server with build version using web service present on the target.
A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
Solution
Refer to VMware advisory VMSA-2022-0030 for more information.
Vendor References
- VMSA-2022-0030 -
www.vmware.com/security/advisories/VMSA-2022-0030.html
CVEs related to QID 216306
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0030 |
|