QID 376190
Date Published: 2021-12-20
QID 376190: VMware NSX-T Man-in-the-Middle (MITM) Vulnerability (VMSA-2020-0023)
VMware NSX-T Data Center provides an agile software-defined infrastructure to build cloud-native application environments.
VMware NSX-T contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.5.
Affected Versions
VMware NSX-T versions 2.5.x prior to 2.5.2.2.0
VMware NSX-T versions 3.x prior to 3.0.2
QID Detection Logic (Authenticated):
The QID checks the vulnerable version of VMware NSX-T.
A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node.
Refer to VMware advisory VMSA-2020-0023 for more information.
- VMSA-2020-0023 -
www.vmware.com/security/advisories/VMSA-2020-0023.html
CVEs related to QID 376190
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2020-0023 |
|