Known vulnerabilities in vCenter Server 6.5 U3l

Vendor: Broadcom
Version: 6.5 U3l
Software CPE: cpe:2.3:a:broadcom:vcenter-server:*:*:*:*:*:*:*:*
Total vulnerabilities: 20
Public exploits: 4
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting vCenter Server version 6.5 U3l vCenter Server 6.5 U3l is affected by 20 vulnerabilities: 1 critical, 1 high, 13 medium, 5 low Critical High Medium Low

Vulnerabilities (20)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU70080 - Improper input validation
CVE-2022-31698
CWE-20 Medium
Public exploit available
No
6.5 U3u, 6.7 U3s, 7.0 U3i 09.12.2022 SB2022120903
SB2023040648
#VU70079 - Information Exposure Through Log Files
CVE-2022-31697
CWE-532 Low
No
No
6.5 U3u, 6.7 U3s, 7.0 U3i 09.12.2022 SB2022120903
SB2023040648
SB2023051945
and 1 more
#VU67978 - Deserialization of Untrusted Data
CVE-2022-31680
CWE-502 Low
No
No
6.5 U3u 07.10.2022 SB2022100705
SB2022112255
SB2023040649
#VU65211 - Server-Side Request Forgery (SSRF)
CVE-2022-22982
CWE-918 Medium
No
No
6.5 U3t, 6.7 U3r, 7.0 U3f 12.07.2022 SB2022071255
SB2022081126
#VU61690 - Incorrect Default Permissions
CVE-2022-22948
CWE-276 High
Public exploit available
Exploited
6.5 U3r, 6.7 U3p, 7.0 U3d 29.03.2022 SB2022032919
SB2022092726
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Public exploit available
Exploited
- 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU58330 - Server-Side Request Forgery (SSRF)
CVE-2021-22049
CWE-918 Medium
No
No
6.5 U3r, 6.7 U3p 23.11.2021 SB2021112316
SB2022010422
SB2022081505
#VU58329 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-21980
CWE-22 Medium
No
No
6.5 U3r, 6.7 U3p 23.11.2021 SB2021112316
SB2022010422
SB2022081505
#VU56808 - Improper input validation
CVE-2021-22019
CWE-20 Medium
No
No
6.5 U3q, 6.7 U3o, 7.0 U2c 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56806 - Improper Authorization
CVE-2021-22017
CWE-285 Medium
No
Exploited
6.5 U3q, 6.7 U3o 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56804 - Incorrect Default Permissions
CVE-2021-22015
CWE-276 Low
Public exploit available
No
6.5 U3q, 6.7 U3o, 7.0 U2c 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56803 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-22014
CWE-94 Low
No
No
6.5 U3q, 6.7 U3o, 7.0 U2c 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56802 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-22013
CWE-22 Medium
No
No
6.5 U3q 21.09.2021 SB2021092117
SB2021092918
SB2021101003
and 1 more
#VU56801 - Improper Authentication
CVE-2021-22012
CWE-287 Medium
No
No
6.5 U3q 21.09.2021 SB2021092117
SB2021092918
SB2021101003
and 1 more
#VU56800 - Improper Authentication
CVE-2021-22011
CWE-287 Medium
No
No
6.5 U3q, 6.7 U3o, 7.0 U2d 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56798 - Resource exhaustion
CVE-2021-22009
CWE-400 Medium
No
No
6.5 U3q, 6.7 U3o, 7.0 U2c 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56797 - Exposure of sensitive information to an unauthorized actor
CVE-2021-22008
CWE-200 Medium
No
No
6.5 U3q, 6.7 U3o, 7.0 U2c 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56793 - Server-Side Request Forgery (SSRF)
CVE-2021-21993
CWE-918 Medium
No
No
6.5 U3q, 6.7 U3o, 7.0 U2c 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56792 - Improper input validation
CVE-2021-21992
CWE-20 Medium
No
No
6.5 U3q, 6.7 U3o, 7.0 U2c 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56791 - Permissions, Privileges, and Access Controls
CVE-2021-21991
CWE-264 Low
No
No
6.5 U3q, 6.7 U3o, 7.0 U2c 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more