QID 371526
Date Published: 2021-09-16
QID 371526: VMware NSX-T Privilege Escalation Vulnerability (VMSA-2021-0006)
VMware NSX-T Data Center provides an agile software-defined infrastructure to build cloud-native application environments.
VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role-based access control) role assignment.
Affected Versions
VMware NSX-T 3.1.1
QID Detection Logic (Authenticated):
The QID checks the vulnerable version of VMware NSX-T.
Note: Unable to check the Workaround suggested by the vendor, hence QID is marked as a 'Potential'.
Successful exploitation of this issue may allow attackers with a local guest user account to assign privileges higher than their own permission level.
Workaround:
Vendor has suggested following workaround to mitigate the issue.
Do not activate local guest user and/or do not assign RBAC role with user-role assignment permission to local guest users.
Please visit here for more information
- VMSA-2021-0006 -
www.vmware.com/security/advisories/VMSA-2021-0006.html
CVEs related to QID 371526
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMware NSX-T 3.1.2 |
|