Improper access control in vCenter Server - CVE-2023-34056
Published: October 25, 2023 / Updated: September 4, 2024
Vulnerability identifier: #VU82354
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34056
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and gain unauthorized access to sensitive information.
Affected software
vCenter Server
PowerFlex Appliance
PowerFlex rack
IBM Cloud Pak System
Dell EMC VxRail Appliance
PowerFlex Appliance
PowerFlex rack
IBM Cloud Pak System
Dell EMC VxRail Appliance
How to mitigate CVE-2023-34056
Install updates from vendor's website.
vCenter Server - addressed in versions 7.0 U3o, 8.0 U2
PowerFlex Appliance - update to IC-45.373.01
IBM Cloud Pak System - update to 2.3.3.6 iFix 2
PowerFlex rack - update to 3.7.3.1
Dell EMC VxRail Appliance - update to 8.0.120
PowerFlex Appliance - update to IC-45.373.01
IBM Cloud Pak System - update to 2.3.3.6 iFix 2
PowerFlex rack - update to 3.7.3.1
Dell EMC VxRail Appliance - update to 8.0.120