CVE-2024-22275

The vCenter Server contains a partial file read vulnerability.A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vmwareCNA
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
vmwarecloud_foundation
4.0 ≤
𝑥
< 5.1.1
vmwarevcenter_server
7.0
vmwarevcenter_server
7.0:a
vmwarevcenter_server
7.0:b
vmwarevcenter_server
7.0:c
vmwarevcenter_server
7.0:d
vmwarevcenter_server
7.0:update1
vmwarevcenter_server
7.0:update1a
vmwarevcenter_server
7.0:update1c
vmwarevcenter_server
7.0:update1d
vmwarevcenter_server
7.0:update2
vmwarevcenter_server
7.0:update2a
vmwarevcenter_server
7.0:update2b
vmwarevcenter_server
7.0:update2c
vmwarevcenter_server
7.0:update2d
vmwarevcenter_server
7.0:update3
vmwarevcenter_server
7.0:update3a
vmwarevcenter_server
7.0:update3c
vmwarevcenter_server
7.0:update3d
vmwarevcenter_server
7.0:update3e
vmwarevcenter_server
7.0:update3f
vmwarevcenter_server
7.0:update3g
vmwarevcenter_server
7.0:update3h
vmwarevcenter_server
7.0:update3i
vmwarevcenter_server
7.0:update3j
vmwarevcenter_server
7.0:update3k
vmwarevcenter_server
7.0:update3l
vmwarevcenter_server
7.0:update3m
vmwarevcenter_server
7.0:update3n
vmwarevcenter_server
7.0:update3o
vmwarevcenter_server
7.0:update3p
vmwarevcenter_server
8.0
vmwarevcenter_server
8.0:a
vmwarevcenter_server
8.0:b
vmwarevcenter_server
8.0:c
vmwarevcenter_server
8.0:update1
vmwarevcenter_server
8.0:update1a
vmwarevcenter_server
8.0:update1b
vmwarevcenter_server
8.0:update1c
vmwarevcenter_server
8.0:update1d
vmwarevcenter_server
8.0:update1e
vmwarevcenter_server
8.0:update2
vmwarevcenter_server
8.0:update2a
𝑥
= Vulnerable software versions