Back to Vulnerabilities
CVE-2023-20887
Critical
vCenter Server

VMware vCenter Server Authentication Bypass Vulnerability

John Smith
4582 views

Summary

A critical authentication bypass vulnerability in VMware vCenter Server allows attackers to gain unauthorized access to the system.

Description

VMware vCenter Server contains an authentication bypass vulnerability in the vSphere Authentication Proxy service. A malicious actor with network access to vCenter Server may be able to bypass authentication controls gaining access to sensitive data.

The vulnerability affects the vSphere Authentication Proxy service which is used to enable ESXi hosts to join an Active Directory domain without requiring the host to have an Active Directory account.

Affected Products

  • vCenter Server 8.0 before 8.0 U1c
  • vCenter Server 7.0 before 7.0 U3n
  • vCenter Server 6.7 before 6.7 U3r

CVSS Score

9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

About the Author

John Smith

Security Researcher

John specializes in virtualization security and has discovered multiple vulnerabilities in VMware products.