VMware Cloud Foundation是美国VMware公司的一套一体化混合云平台。该平台包括运维自动化、基础架构自动配置和集成式生命周期管理等功能。 VMware Cloud Foundation存在授权问题漏洞,该漏洞源于VMware Directory Service存在认证绕过漏洞,可能导致具有网络访问权限的攻击者绕过认证并获得未授权访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x |
affected |
9.0.x.x |
affected | ||
5.x |
affected | ||
| VMware | Telco Cloud Infrastructure | 3.0 |
affected |
| VMware | Telco Cloud Platform | 5.1.x |
affected |
5.0.x |
affected | ||
4.x |
affected | ||
3.0 |
affected | ||
| VMware | vCenter | 9.1.x.x< 9.1.0.0300 |
affected |
9.0.x.x< 9.0.2.0100 |
affected | ||
8.0< 8.0 U3k |
affected | ||
| VMware | vSphere Foundation | 9.1.x.x |
affected |
9.0.x.x |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x | - |
|
| VMware | vSphere Foundation | 9.1.x.x | - |
|
| VMware | vCenter | 9.1.x.x ~ 9.1.0.0300 | - |
|
| VMware | Telco Cloud Infrastructure | 3.0 | - |
|
| VMware | Telco Cloud Platform | 5.1.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-59310 | 9.8 CRITICAL | vCenter directory-traversal vulnerability |
| CVE-2026-47876 | 9.3 CRITICAL | VMXNET3 out-of-bounds write vulnerability |
| CVE-2026-41703 | 7.6 HIGH | Out-of-bounds read vulnerability |
| CVE-2026-41709 | 2.7 LOW | ESX insufficient logging vulnerability |
No comments yet