CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2024-37085

🔥 Known Exploited (CISA KEV)MEDIUM
6.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-06-25
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

Affected Platforms (CPE)

📦
Vmware

Cloud Foundation

>= 4.0 and < 5.2
💻
Vmware

Esxi

= 7.0= 8.0

References & Advisories

相關資安分析文章

相關漏洞威脅

CVE-2024-37085 Detail & Impact Analysis | CVSS 6.8 (MEDIUM) | Cyber-Sec.Space | Cyber-Sec.Space