QID 730669
Date Published: 2022-11-17
QID 730669: VMware NSX Manager Remote Code Execution (RCE) Vulnerability (VMSA-2022-0027)
VMWare NSX Manager is vulnerable to a pre-authenticated remote code execution vulnerability via XStream open source library. (CVE-2021-39144)
Affected Versions:
VMware Cloud Foundation (NSX-V) 3.11
QID Detection Logic (Unauthenticated): This QID sends a crafted payload to VMware NSX target and checks for a callback. A vulnerable target will connect back to the Qualys scanner on a specified port.
Due to an unauthenticated endpoint that leverages XStream for input serialization in VMware Cloud Foundation (NSX-V), a malicious actor can get remote code execution in the context of 'root' on the appliance.
Solution
Vendor has released patch to address the vulnerability. For more information please refer to VMSA-2022-0027
Vendor References
- VMSA-2022-0027.html -
www.vmware.com/security/advisories/VMSA-2022-0027.html
CVEs related to QID 730669
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0027 |
|