First published: Wed Oct 16 2024(Updated: )
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager. Updates are available to remediate this vulnerability in affected VMware products.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware HCX | >=4.8.0<=4.8.2 | |
VMware HCX | >=4.9.0<=4.9.1 | |
VMware HCX | =4.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38814 is considered a critical vulnerability due to its potential to allow unauthorized remote code execution.
To address CVE-2024-38814, update VMware HCX to the latest version that mitigates this vulnerability.
CVE-2024-38814 affects authenticated users of VMware HCX with non-administrator privileges.
Yes, the exploitation of CVE-2024-38814 can potentially lead to unauthorized access and data breaches.
Versions of VMware HCX from 4.8.0 to 4.8.2, 4.9.0 to 4.9.1, and the exact version 4.10.0 are vulnerable to CVE-2024-38814.