Impact
VMware vCenter contains an authentication bypass flaw in the VMware Directory Service. A malicious actor who can reach the vCenter management interface over the network can exploit this weakness to bypass authentication and gain unauthorized access to the system. The CWE-303 weakness undermines fundamental authorization checks, allowing an attacker to assume any user identity without providing credentials. The impact is that the attacker can perform operations available to the authenticated user, potentially accessing or modifying system resources and data. The description does not specify further capabilities beyond the bypass itself.
Affected Systems
Affected vendors include VMware. Impacted products are Cloud Foundation, Telco Cloud Infrastructure, Telco Cloud Platform, vCenter Server, and vSphere Foundation. Affected versions include vCenter Server 8.0 and all its subsequent releases up to and including update3j, as well as the various minor updates listed (e.g., update1, update1a, update1b, update1c, update1d, update1e, update1*, update2a, update2b, update2c, update2d, update2e, update3a, update3b, update3c, update3d, update3e, update3g, update3h, update3i, update3j). Telco Cloud Infrastructure 3.0 is also affected. Cloud Foundation and vSphere Foundation are affected in all releases as indicated by the CPE strings.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is reported as < 1%, showing a very low probability of exploitation in the wild, although the lack of KEV listing does not reduce potential damage. An attacker only needs network access to the vCenter management interface; no additional privileges are required before exploitation. After the authentication bypass is achieved, the attacker can carry out any actions that are permitted for the user account they assume. The direct attack path is straightforward, but the high impact warrants immediate action.
OpenCVE Enrichment