Description
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
CISA Known Exploited Vulnerability
Date added 2024-11-20 | Due date 2024-12-11
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Problem types
CWE-273 Improper Check for Dropped Privileges
Product status
8.0 (custom) before 8.0 U3b
7.0 (custom) before 7.0 U3s
5.x
4.x
References
www.cisa.gov/...erabilities-catalog?field_cve=CVE-2024-38813
support.broadcom.com/...l/content/SecurityAdvisories/0/24968