Improper access control in vCenter Server - CVE-2023-34056

 

Improper access control in vCenter Server - CVE-2023-34056

Published: October 25, 2023 / Updated: September 4, 2024


Vulnerability identifier: #VU82354
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34056
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and gain unauthorized access to sensitive information.


Affected software

vCenter Server
PowerFlex Appliance
PowerFlex rack
IBM Cloud Pak System
Dell EMC VxRail Appliance

How to mitigate CVE-2023-34056

Install updates from vendor's website.

vCenter Server - addressed in versions 7.0 U3o, 8.0 U2
PowerFlex Appliance - update to IC-45.373.01
IBM Cloud Pak System - update to 2.3.3.6 iFix 2
PowerFlex rack - update to 3.7.3.1
Dell EMC VxRail Appliance - update to 8.0.120

External References

Related Security Bulletins