Lucene search

K
ubuntuUbuntuUSN-6257-1
HistoryJul 27, 2023 - 12:00 a.m.

Open VM Tools vulnerability

2023-07-2700:00:00
ubuntu.com
40
ubuntu
open vm tools
vulnerability
authentication
esxi host
guest virtual machine
confidentiality
integrity
cve-2023-20867

3.9 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

5.1 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.6%

Releases

  • Ubuntu 23.04
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • open-vm-tools - Open VMware Tools for virtual machines hosted on VMware

Details

It was discovered that Open VM Tools incorrectly handled certain
authentication requests. A fully compromised ESXi host can force Open VM
Tools to fail to authenticate host-to-guest operations, impacting the
confidentiality and integrity of the guest virtual machine. (CVE-2023-20867)

OSVersionArchitecturePackageVersionFilename
Ubuntu23.04noarchopen-vm-tools< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-containerinfo< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-containerinfo-dbgsym< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-dbgsym< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-desktop< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-desktop-dbgsym< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-dev< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-salt-minion< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-sdmp< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Ubuntu23.04noarchopen-vm-tools-sdmp-dbgsym< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
Rows per page:
1-10 of 391

3.9 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

5.1 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.6%