CVE-2024-38813

Published Sep 17, 2024

Last updated a month ago

Overview

Description
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
Source
security@vmware.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-273
security@vmware.com
CWE-250

Social media

Hype score
Not currently trending
  1. VMware məhsullarında boşluq (CVE-2024-38813) aşkar olunub. #ETX #certaz #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/7wVzUygTCP

    @CERTAzerbaijan

    28 Oct 2024

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Broadcom releases patches for critical VMware vCenter Server vulnerabilities (CVE-2024-38812, CVE-2024-38813). CVE-2024-38812 (CVSS 9.8) allows remote code execution in versions 7.0, 8.0 & Cloud Foundation. Immediate patching is recommended. #cve #infosec #broadcom #vm #rc

    @paramdhagia

    22 Oct 2024

    39 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. VMware vCenter Server Vulnerabilities Let Attackers Execute Remote Code: https://t.co/2lFo9hpG1D Broadcom released critical updates for VMware vCenter Server to address vulnerabilities CVE-2024-38812 and CVE-2024-38813, which allow remote code execution and privilege escalation,

    @securityRSS

    22 Oct 2024

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812): Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter Server, one of which hasn’t been fully addressed the first time and… https://t.co/rm9ZBcvsUf

    @cipherstorm

    22 Oct 2024

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812): Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter Server, one of which hasn’t been fully addressed the first time and… https://t.co/6J6D2cdLbt

    @shah_sheikh

    22 Oct 2024

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations