OS Command Injection in vCenter Server - CVE-2024-22274

 

OS Command Injection in vCenter Server - CVE-2024-22274

Published: September 4, 2024 / Updated: December 13, 2024


Vulnerability identifier: #VU96787
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22274
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote user with administrative privileges on the vCenter appliance shell execute arbitrary OS commands on the target system.


Affected software

vCenter Server
IBM Cloud Pak System
PowerProtect DP Series Appliance (IDPA)

How to mitigate CVE-2024-22274

Install updates from vendor's website.

vCenter Server - addressed in versions 7.0 U3q, 8.0 U2b
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins