VMware Cloud Foundation是美国VMware公司的一套一体化混合云平台。该平台包括运维自动化、基础架构自动配置和集成式生命周期管理等功能。 VMware Cloud Foundation存在路径遍历漏洞,该漏洞源于Syslog服务器存在目录遍历漏洞,可能导致具有网络访问权限的攻击者执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x |
affected |
9.0.x.x |
affected | ||
5.x |
affected | ||
| VMware | Telco Cloud Infrastructure | 3.0 |
affected |
| VMware | Telco Cloud Platform | 5.1.x |
affected |
5.0.x |
affected | ||
4.x |
affected | ||
3.0 |
affected | ||
| VMware | vCenter | 9.1.x.x< 9.1.0.0300 |
affected |
9.0.x.x< 9.0.2.0100 |
affected | ||
8.0< 8.0 U3k |
affected | ||
| VMware | vSphere Foundation | 9.1.x.x |
affected |
9.0.x.x |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x | - |
|
| VMware | vSphere Foundation | 9.1.x.x | - |
|
| VMware | vCenter | 9.1.x.x ~ 9.1.0.0300 | - |
|
| VMware | Telco Cloud Infrastructure | 3.0 | - |
|
| VMware | Telco Cloud Platform | 5.1.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-59309 | 9.8 CRITICAL | vCenter authentication-bypass vulnerability |
| CVE-2026-47876 | 9.3 CRITICAL | VMXNET3 out-of-bounds write vulnerability |
| CVE-2026-41703 | 7.6 HIGH | Out-of-bounds read vulnerability |
| CVE-2026-41709 | 2.7 LOW | ESX insufficient logging vulnerability |
No comments yet