Impact
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi allows an attacker to gain elevated privileges, potentially culminating in arbitrary code execution. The flaw arises within the driver's memory handling, which can be exploited to overwrite critical control data.
Affected Systems
AMD:ESXi 8.x and ESXi 9.x hosts that use AMD‑Pensando DPU products are affected. No specific sub‑versions are listed, but all releases of the specified host versions that include the ionic cloud driver are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. EPSS data is not available, so the current exploitation probability is uncertain. The vulnerability is not included in the CISA KEV catalog, but its impact level warrants immediate attention. Attackers would need to target the specific ESXi hosts equipped with the affected DPU drivers; the exact attack vector is not disclosed in the advisory.
OpenCVE Enrichment