ZDI-23-114: VMware vRealize Log Insight addClusterCACertificate Deserialization of Untrusted Data Denial-of-Service Vulnerability
Published Feb 9, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of VMware vRealize Log Insight. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
VMware vRealize Log Insight
Event History
Feb 9, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-114?
The severity of ZDI-23-114 is critical due to its potential to cause a denial-of-service condition.
2
How do I fix ZDI-23-114?
To fix ZDI-23-114, update your VMware vRealize Log Insight to the latest version provided by VMware.
3
What types of attacks can exploit ZDI-23-114?
ZDI-23-114 can be exploited by remote attackers to create a denial-of-service condition.
4
Is authentication required to exploit ZDI-23-114?
No, authentication is not required to exploit ZDI-23-114.
5
Which software is affected by ZDI-23-114?
ZDI-23-114 affects installations of VMware vRealize Log Insight.