VMware Cloud Foundation是美国VMware公司的一套一体化混合云平台。该平台包括运维自动化、基础架构自动配置和集成式生命周期管理等功能。 VMware Cloud Foundation存在授权问题漏洞,该漏洞源于VMware Directory Service存在认证绕过漏洞,可能导致具有网络访问权限的攻击者绕过认证并获得未授权访问。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x |
affected |
9.0.x.x |
affected | ||
5.x |
affected | ||
| VMware | Telco Cloud Infrastructure | 3.0 |
affected |
| VMware | Telco Cloud Platform | 5.1.x |
affected |
5.0.x |
affected | ||
4.x |
affected | ||
3.0 |
affected | ||
| VMware | vCenter | 9.1.x.x< 9.1.0.0300 |
affected |
9.0.x.x< 9.0.2.0100 |
affected | ||
8.0< 8.0 U3k |
affected | ||
| VMware | vSphere Foundation | 9.1.x.x |
affected |
9.0.x.x |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x | - |
|
| VMware | vSphere Foundation | 9.1.x.x | - |
|
| VMware | vCenter | 9.1.x.x ~ 9.1.0.0300 | - |
|
| VMware | Telco Cloud Infrastructure | 3.0 | - |
|
| VMware | Telco Cloud Platform | 5.1.x | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
| CVE-2026-59310 | 9.8 CRITICAL | VMware Cloud Foundation 路径遍历漏洞 |
| CVE-2026-47876 | 9.3 CRITICAL | VMware Cloud Foundation 缓冲区错误漏洞 |
| CVE-2026-41703 | 7.6 HIGH | VMware Cloud Foundation 缓冲区错误漏洞 |
| CVE-2026-41709 | 2.7 LOW | VMware Cloud Foundation 日志信息泄露漏洞 |
暂无评论