HomeSecurityVMware: Critical Identity Bypass in VCD Appliance

VMware: Critical Identity Bypass in VCD Appliance

VMware has disclosed a critical and unpatched authentication bypass vulnerability affecting VCD Appliance installations.

See also: VMware: Publicly exploiting RCE flaw in vRealize
VMware

Cloud Director allows VMware administrators to manage their organizations' cloud services as part of Virtual Data Centers (VDCs)

The security vulnerability only affects devices running VCD Appliance 10.5 that were previously upgraded from an older version. The company also added that CVE-2023-34060 does not affect new installations of VCD Appliance 10.5, Linux , and other devices.

Unauthorized attackers can remotely exploit the flaw with low-sophistication attacks that do not require user interaction.

According to VMware, “in an upgraded version of VMware Cloud Director Appliance 10.5, a malicious user with access to the appliance’s network can bypass authentication connection restrictions on port 22 (ssh) or port 5480 (appliance management console).“

“This override does not exist on port 443 (VCD provider and tenant connection). On a fresh installation of VMware Cloud Director Appliance 10.5, the override does not exist.“

Although VMware does not yet have a patch for this critical authentication bypass bug, the company has provided administrators with a temporary workaround until security updates are released.

See also: VMware users worried about ransomware threats

“VMware has published VMware Security Advisory VMSA-2023-0026 to help customers understand the issue and which update will fix it,” VMware said in a separate statement.

VCD Appliance

The temporary solution shared by VMware will only work for affected versions of VCD Appliance 10.5.0 and requires downloading a custom script that accompanies this article and running it on cells exposed to the CVE-2023-34060 vulnerability.

According to VMware, the temporary solution does not cause any disruption to operations and the downtime is not long, as a service or system reboot is not necessary.

In June, the company also patched an ESXi zero-day used by Chinese hackers to steal data and notified customers of an actively exploited critical flaw in its Aria Operations network analytics tool.

Recently, in October, it fixed a serious vCenter Server vulnerability (CVE-2023-34048) that can be exploited for remote code execution attacks

See also: VMware Aria: Vulnerable to critical SSH authentication bypass vulnerability

VMware VCD Appliance is a desktop provided by VMware for managing and delivering cloud services. It is a software-as-a-service (SaaS) platform that allows users to create and manage virtual machines, storage, networks, and other resources in the cloud computing space.

VCD stands for VMware Cloud Director and refers to VMware's Infrastructure as a Service (IaaS) management platform. The purpose of the VCD Appliance is to provide a flexible and secure environment for deploying and delivering cloud services to an enterprise or organization.

With VMware VCD Appliance, users can create and manage virtual machines, provision storage and networking, manage security , and deliver services to their users. It also provides automation and orchestration capabilities for administrators' convenience.

The VCD Appliance architecture is based on a central database and includes various services and subsystems for managing cloud resources. Users can access the VCD Appliance through a user interface provided through a browser or through an API.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS