Advisory Published


First published: Tue Nov 14 2023(Updated: )

VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . This bypass is not present on port 443 (VCD provider and tenant login). On a new installation of VMware Cloud Director Appliance 10.5, the bypass is not present. VMware Cloud Director Appliance is impacted since it uses an affected version of sssd from the underlying Photon OS. The sssd issue is no longer present in versions of Photon OS that ship with sssd-2.8.1-11 or higher (Photon OS 3) or sssd-2.8.2-9 or higher (Photon OS 4 and 5).


Affected SoftwareAffected VersionHow to fix
VMware Cloud Director=10.5
VMware VCD Appliance=10.5
VMware Cloud Director<10.5
VMware Photon OS

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Peer vulnerabilities

(Found alongside the following vulnerabilities)

Frequently Asked Questions

  • What is CVE-2023-34060?

    CVE-2023-34060 is a vulnerability in VMware Cloud Director Appliance that allows an attacker to bypass authentication.

  • How severe is CVE-2023-34060?

    CVE-2023-34060 has a severity rating of 9.8 (Critical).

  • What is the affected software by CVE-2023-34060?

    The affected software is VMware Cloud Director Appliance version 10.5.

  • How can an attacker exploit CVE-2023-34060?

    An attacker with network access to the VMware Cloud Director Appliance can bypass login authentication.

  • Where can I find more information about CVE-2023-34060?

    You can find more information about CVE-2023-34060 in the VMware security advisory:


SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203