VMware vCenter Server
cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*
- 8.0
- 7.0
An authenticated command-execution vulnerability has been identified in VMware vCenter Server. This issue allows a malicious actor with privileges to create or modify alarms and execute script actions to run arbitrary commands on the vCenter Server.
Exploitation of this vulnerability could lead to unauthorized command execution on the affected vCenter Server.
To address this vulnerability, users should apply the updates available for their version of vCenter Server. Instructions for downloading the patch can be found in the VMware vCenter Server 8.0 U3e and 7.0 U3v release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.