Out-of-bounds read in vCenter Server - CVE-2023-20895

 

Out-of-bounds read in vCenter Server - CVE-2023-20895

Published: June 22, 2023


Vulnerability identifier: #VU77638
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20895
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in DCERPC protocol implementation. A remote attacker can send specially crafted traffic to the server to trigger an out-of-bounds read error and read contents of memory on the system. The obtain information can be used to bypass authentication process and compromise the system.


Affected software

vCenter Server
Dell EMC VxRail Appliance

How to mitigate CVE-2023-20895

Install updates from vendor's website.

vCenter Server - addressed in versions 7.0 U3m, 8.0 U1b
Dell EMC VxRail Appliance - update to 8.0.101

External References

Related Security Bulletins