Out-of-bounds read in vCenter Server - CVE-2023-20895
Published: June 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in DCERPC protocol implementation. A remote attacker can send specially crafted traffic to the server to trigger an out-of-bounds read error and read contents of memory on the system. The obtain information can be used to bypass authentication process and compromise the system.
Affected software
Dell EMC VxRail Appliance
How to mitigate CVE-2023-20895
Dell EMC VxRail Appliance - update to 8.0.101