CVE-2023-20896: High severity vmware vcenter vulnerability
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20896?
CVE-2023-20896 is an out-of-bounds read vulnerability in the implementation of the DCERPC protocol in VMware vCenter Server.
What is the severity of CVE-2023-20896?
The severity of CVE-2023-20896 is high with a CVSS score of 7.5.
How can a malicious actor exploit CVE-2023-20896?
A malicious actor with network access to vCenter Server can trigger an out-of-bounds read by sending a specially crafted packet, leading to denial-of-service of certain services.
Which versions of VMware vCenter Server are affected by CVE-2023-20896?
VMware vCenter Server versions 4.0 to 7.0 are affected by CVE-2023-20896.
How can I fix CVE-2023-20896?
VMware has released security advisories with patches addressing CVE-2023-20896. It is recommended to apply the necessary patches or updates to mitigate the vulnerability.