QID 216307

Date Published: 2023-02-07

QID 216307: VMware vCenter Server 7.0 Update 7.0 U3i (VMSA-2022-0030)

VMware vCenter Server is a server management solution that helps IT admins manage virtualized hosts and virtual machines in enterprise environments via a single console.

Affected Versions:
VMware vCenter Server Virtual Appliance 6.7 prior to build 20845200

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware vCenter Server with build version using web service present on the target.

A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 3.6 severity.
  • Solution

    Refer to VMware advisory VMSA-2022-0030 for more information.

    CVEs related to QID 216307

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0030 URL Logo www.vmware.com/security/advisories/VMSA-2022-0030.html