Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-20867

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.4%
CVSS Severity
CVSS v3 Score 3.9
Proposed Action
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.
Ransomware Campaign
Unknown
References
Products affected by CVE-2023-20867
  • Vmware » Tools » Version: 10.3.0
    cpe:2.3:a:vmware:tools:10.3.0
  • Vmware » Tools » Version: 10.3.10
    cpe:2.3:a:vmware:tools:10.3.10
  • Vmware » Tools » Version: 10.3.2
    cpe:2.3:a:vmware:tools:10.3.2
  • Vmware » Tools » Version: 10.3.20
    cpe:2.3:a:vmware:tools:10.3.20
  • Vmware » Tools » Version: 10.3.21
    cpe:2.3:a:vmware:tools:10.3.21
  • Vmware » Tools » Version: 10.3.22
    cpe:2.3:a:vmware:tools:10.3.22
  • Vmware » Tools » Version: 10.3.25
    cpe:2.3:a:vmware:tools:10.3.25
  • Vmware » Tools » Version: 10.3.26
    cpe:2.3:a:vmware:tools:10.3.26
  • Vmware » Tools » Version: 10.3.5
    cpe:2.3:a:vmware:tools:10.3.5
  • Vmware » Tools » Version: 11.0.0
    cpe:2.3:a:vmware:tools:11.0.0
  • Vmware » Tools » Version: 11.0.1
    cpe:2.3:a:vmware:tools:11.0.1
  • Vmware » Tools » Version: 11.0.5
    cpe:2.3:a:vmware:tools:11.0.5
  • Vmware » Tools » Version: 11.1.0
    cpe:2.3:a:vmware:tools:11.1.0
  • Vmware » Tools » Version: 11.1.1
    cpe:2.3:a:vmware:tools:11.1.1
  • Vmware » Tools » Version: 11.1.5
    cpe:2.3:a:vmware:tools:11.1.5
  • Vmware » Tools » Version: 11.2.0
    cpe:2.3:a:vmware:tools:11.2.0
  • Vmware » Tools » Version: 11.2.1
    cpe:2.3:a:vmware:tools:11.2.1
  • Vmware » Tools » Version: 11.2.5
    cpe:2.3:a:vmware:tools:11.2.5
  • Vmware » Tools » Version: 11.2.6
    cpe:2.3:a:vmware:tools:11.2.6
  • Vmware » Tools » Version: 11.3.0
    cpe:2.3:a:vmware:tools:11.3.0
  • Vmware » Tools » Version: 12.1.0
    cpe:2.3:a:vmware:tools:12.1.0
  • Vmware » Tools » Version: 12.1.1
    cpe:2.3:a:vmware:tools:12.1.1
  • Vmware » Tools » Version: 12.1.5
    cpe:2.3:a:vmware:tools:12.1.5
  • Vmware » Tools » Version: 12.2.0
    cpe:2.3:a:vmware:tools:12.2.0
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 11.0
    cpe:2.3:o:debian:debian_linux:11.0
  • Debian » Debian Linux » Version: 12.0
    cpe:2.3:o:debian:debian_linux:12.0
  • Fedoraproject » Fedora » Version: 37
    cpe:2.3:o:fedoraproject:fedora:37
  • Fedoraproject » Fedora » Version: 38
    cpe:2.3:o:fedoraproject:fedora:38
  • Fedoraproject » Fedora » Version: 39
    cpe:2.3:o:fedoraproject:fedora:39


Contact Us

Shodan ® - All rights reserved