VMware patches major security flaw in cloud service-delivery platform


VMware has patched a serious flaw in its cloud service-delivery platform, VMware Cloud Director, after cybersecurity firm Citadelo issued a security advisory warning of possible threats.
Citadelo said that it uncovered the bug on April 1 while conducting a security audit for a Fortune 500 enterprise client that was using VMware Cloud Director. The software has been adopted by enterprises and cloud service vendors worldwide.
The penetration testing firm attributed the bug in VMware Cloud Director, which facilitates hosting of automation tools, cloud migration, virtual data centre management and data centre expansion, to the platform’s inability to handle input properly.
VMware response
Hackers can capitalise on the vulnerability—tracked as CVE-2020-3956—to carry out perform code execution attacks and “technically” assume control over all private clouds linked to the given infrastructure, Citadelo warned.
The bug impacts VMware Cloud Director versions 10.1.0 and below, as well as vCloud Director 8x – 10x on Linux setups and PhotonOS appliances.
Citadelo added that potential consequences of cyber miscreants exploiting the bug could span credential theft via altering of log-in mechanisms, escalation of privileges from organisation administrators to vCloud admins, and tampering of virtual machines through database modification.
As part of its exhaustive analysis of the vulnerability, the cybersecurity firm said that it could read email, IP addresses and other confidential client data, besides gaining access to internal system databases containing password hashes—including customer allocations.
Responding to the advisory, VMware described the bug, which received a severity CVSSV3 score of 8.8, as “important”, and provisioned patches as well as a workaround that is cited in its Knowledge Base.
The cloud computing and virtualisation software provider acknowledged that authenticated actors could possibly route “malicious traffic” its cloud service-delivery platform, known as vCloud Director earlier, thereby triggering execution of arbitrary remote code.
Hackers could exploit the flaw in VMware Cloud Director via Flex- and HTML5-based user interfaces, the API Explorer interface and API access, VMware noted.
After the bug came to light, the company triaged and reproduced it on April 3, resulting in the build of a patch on April 30. Subsequently, VMware made a disclosure regarding the same in May, to enable users of VMware Cloud Director to patch their builds in time. Finally, VMware unveiled a security advisory to its clients on May 19.
Via: ZDNet
VMware has patched a serious flaw in its cloud service-delivery platform, VMware Cloud Director, after cybersecurity firm Citadelo issued a security advisory warning of possible threats. Citadelo said that it uncovered the bug on April 1 while conducting a security audit for a Fortune 500 enterprise client that was using…
Recent Posts
- Razer’s new Blade 18 offers Nvidia RTX 50-series GPUs and a dual mode display
- I tried adding audio to videos in Dream Machine, and Sora’s silence sounds deafening in comparison
- Sandisk quietly introduced an 8TB version of its popular portable SSD, and I just hope they solved its previous big data corruption issue
- iPhones are briefly changing ‘racist’ to ‘Trump’ due to an iOS dictation issue
- We finally know who’s legally running DOGE
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010