Vulnerability: CVE-2023-51384 and CVE-2023-51385 on VMware vCenter Server
search cancel

Vulnerability: CVE-2023-51384 and CVE-2023-51385 on VMware vCenter Server

book

Article ID: 370007

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

 Vulnerability scanners detect the following OpenSSH vulnerabilities in the environment:

  • CVE-2023-51384: Priority Medium (CVSS 5.5)
  • CVE-2023-51385: Priority Medium (CVSS 5.5)

Environment

  • VMware vCenter Server 7.x
  • VMware vCenter Server 8.x

Resolution

  • These vulnerabilities are resolved in the following releases:

    • vCenter Server 8.x: Resolved in vCenter 8.0 U3.
    • vCenter Server 7.x:
      • CVE-2023-51384: Not applicable. This vulnerability affects OpenSSH version 8.9 and above; vCenter 7.x utilizes OpenSSH 7.8p1.
      • CVE-2023-51385: Resolved in vCenter 7.0 U3v.

Additional Information

  • Since OpenSSH is one of the packages which comes as a complete installation bundle with VMware vCenter Server we cannot upgrade it to specific version.
  • Keep SSH disabled on your host unless it is required for troubleshooting purpose
  • This CVE is affected to the OpenSSH version 8.9 and above
  • Run the following command on the vCenter SSH to verify the version being used in the environment.

rpm -qa | grep -i ssh

  • CVE-2023-51384 and CVE- 2023-51385 vulnerabilities are fixed in OpenSSH 8.9p1-6, which are the makeup of VCSA 8.0.3.00000 (8.0 U3). 
  • There should be no impact from CVE-2023-51384 and CVE- 2023-51385 on VCSA 8.0 U3.
  • If security scanner still reporting them then are false positives.

OpenSSH の脆弱性 (CVE-2023-51384 and CVE- 2023-51385)