Impact
A directory traversal flaw exists in the Syslog server component of VMware vCenter. The vulnerability permits a malicious actor with network access to traverse directories on the host, potentially allowing arbitrary code execution. The weakness aligns with path traversal (CWE-22).
Affected Systems
The flaw impacts VMware Cloud Foundation, VMware Telco Cloud Infrastructure version 3.0, VMware Telco Cloud Platform (all releases), VMware vCenter Server 8.0—including all update streams through update3j—and VMware vSphere Foundation (all releases).
Risk and Exploitability
The CVSS score of 9.8 indicates high severity, and the EPSS score of 46% indicates a high exploitation probability. The vulnerability is listed in the CISA KEV catalog. Exploitation would require an attacker to be reachable over the network to the vCenter Syslog server, after which unvalidated file path processing could lead to code execution.
OpenCVE Enrichment