Back to Vulnerabilities
CVE-2023-20887
Critical
vCenter Server
VMware vCenter Server Authentication Bypass Vulnerability
John Smith
4582 views
Summary
A critical authentication bypass vulnerability in VMware vCenter Server allows attackers to gain unauthorized access to the system.
Description
VMware vCenter Server contains an authentication bypass vulnerability in the vSphere Authentication Proxy service. A malicious actor with network access to vCenter Server may be able to bypass authentication controls gaining access to sensitive data.
The vulnerability affects the vSphere Authentication Proxy service which is used to enable ESXi hosts to join an Active Directory domain without requiring the host to have an Active Directory account.
Affected Products
- vCenter Server 8.0 before 8.0 U1c
- vCenter Server 7.0 before 7.0 U3n
- vCenter Server 6.7 before 6.7 U3r
CVSS Score
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAbout the Author
John Smith
Security Researcher
John specializes in virtualization security and has discovered multiple vulnerabilities in VMware products.