Skip to content

VMware ESXi and vCenter Server multiple vulnerabilities - 20240626001

Overview

The WA SOC has been made aware of multiple vulnerabilities affecting VMware ESXi and vCenter Server.

What is vulnerable?

Products Affected CVE CVSSv3 Severity
versions before
vCenter Server 7.0
vCenter Server 8.0
VMware Cloud Foundation 5.x
VMware Cloud Foundation 4.x
CVE-2024-37085
CVE-2024-37086
CVE-2024-37087
5.3 - 6.8 Medium

What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of one month... (refer Patch Management):

Additional References