OS Command Injection in vCenter Server - CVE-2024-22274
Published: September 4, 2024 / Updated: December 13, 2024
Vulnerability identifier: #VU96787
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22274
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote user with administrative privileges on the vCenter appliance shell execute arbitrary OS commands on the target system.
Affected software
vCenter Server
IBM Cloud Pak System
PowerProtect DP Series Appliance (IDPA)
IBM Cloud Pak System
PowerProtect DP Series Appliance (IDPA)
How to mitigate CVE-2024-22274
Install updates from vendor's website.
vCenter Server - addressed in versions 7.0 U3q, 8.0 U2b
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7