VMware fixes critical Cloud Director auth bypass unpatched for 2 weeks

December 1, 2023 at 01:04PM VMware fixed a critical authentication bypass vulnerability in upgraded Cloud Director appliance 10.5, which allowed remote attackers to exploit it without user interaction. The issue, identified as CVE-2023-34060, did not affect fresh installations, Linux deployments, or other appliances. VMware also provided a workaround script for immediate protection, ensuring no service … Read more

Urgent: VMware Warns of Unpatched Critical Cloud Director Vulnerability

November 14, 2023 at 11:27PM VMware has issued a warning about a critical security flaw in Cloud Director that could allow unauthorized access. The vulnerability affects instances upgraded to version 10.5 and can be exploited to bypass login restrictions on certain ports. A fix has not yet been released, but a workaround is available. This … Read more

VMWare discloses critical VCD Appliance auth bypass with no patch

November 14, 2023 at 04:47PM VMware has disclosed a critical authentication bypass vulnerability affecting Cloud Director appliance deployments. The vulnerability only affects certain versions of the appliance and can be exploited remotely without user interaction. While no patch is available, VMware has provided a temporary workaround that does not disrupt functionality or require downtime. After … Read more