ZDI-CAN-20007: ZDI-24-882: VMware vCenter Server Appliance License Server Uncontrolled Memory Allocation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of VMware vCenter Server Appliance. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2024-37087.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20007?
The CVSS rating assigned to ZDI-CAN-20007 is 5.3, indicating a medium severity vulnerability.
How do I fix ZDI-CAN-20007?
To mitigate ZDI-CAN-20007, apply the latest security patches provided by VMware for vCenter Server Appliance.
Who can exploit ZDI-CAN-20007?
ZDI-CAN-20007 can be exploited by remote attackers without requiring authentication.
What is the impact of ZDI-CAN-20007?
The impact of ZDI-CAN-20007 is the creation of a denial-of-service condition on affected VMware vCenter Server Appliance installations.
When was ZDI-CAN-20007 disclosed?
ZDI-CAN-20007 was disclosed as part of the Zero Day Initiative's advisories.