[VMC on AWS] Third-party security scanning tool reports vulnerability in SDDC
search cancel

[VMC on AWS] Third-party security scanning tool reports vulnerability in SDDC

book

Article ID: 314084

calendar_today

Updated On:

Products

VMware Cloud on AWS

Issue/Introduction

Third-party security scan has reported vulnerabilities in a VMware Cloud on AWS SDDC. 

Environment

VMC on AWS

Cause

  • VMC on AWS SDDCs may run on non-standard builds of vCenter and ESXi and this can cause false positives to occur. 
  • False positives may also occur due to the [email protected] account not having full administrative privileges to management components. 

Resolution

  • All management components in VMC on AWS SDDCs are managed by the Broadcom team following the shared responsibility model. 
  • Scans are regularly run against management components and are mitigated based on Broadcom's response and remediation policy. 
    • Critical: Begin work on a fix or corrective action immediately and provide in the shortest reasonable time
    • Important: Fix is delivered in the next planned maintenance or update
    • Moderate/Low: Fix is delivered in next planned release
  • Most critical vulnerabilities are mitigated in VMC on AWS SDDCs before the vulnerability has been disclosed. 

Additional Information