Impact
A remote attacker who can intercept traffic between a BOSH Director and VMware vCenter can impersonate the vCenter REST API by exploiting insufficient certificate validation (CWE‑295). This flaw allows the attacker to capture HTTP Basic authentication credentials that the BOSH Director transmits for routine CPI operations. Once the vCenter administrator username and password are obtained, the attacker gains full administrative control over every virtual machine, datastore, and network managed by the CPI, enabling a complete takeover of the entire virtualization estate.
Affected Systems
The vulnerability affects the Cloud Foundry bosh‑vsphere‑cpi‑release component. The flaw exists in every CPI call made by the BOSH Director to vCenter, regardless of whether HTTPS is used. All releases of the vSphere CPI that lack proper certificate validation and pinning are impacted, meaning any deployment that relies on this CPI to communicate with vCenter is susceptible.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity impact, and while the EPSS score is not available, the lack of a KEV listing does not diminish the danger if a relevant credential capture can be achieved. The attack requires the attacker to be positioned between the BOSH Director and the vCenter endpoint, typically through a man‑in‑the‑middle or network compromise, to inject a malicious server. The attacker must then capture Basic authentication credentials, after which full administrative privileges are immediately granted. The high CVSS combined with the ability to control the entire virtualization infrastructure makes this a serious risk for any environment using the vulnerable CPI.
OpenCVE Enrichment