CVE-2024-38814

EUVD-2024-37637
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A
 malicious authenticated user with non-administrator privileges may be 
able to enter specially crafted SQL queries and perform unauthorized 
remote code execution on the HCX manager. 
Updates are available to remediate this vulnerability in affected VMware products.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
vmwarevmware_hcx
4.8.0 ≤
𝑥
≤ 4.8.2
vmwarevmware_hcx
4.9.0 ≤
𝑥
≤ 4.9.1
vmwarevmware_hcx
4.10.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
vmwarevmware_hcx
4.8.0 ≤
𝑥
≤ 4.8.2
ADP
vmwarevmware_hcx
4.9.0 ≤
𝑥
≤ 4.9.1
ADP