Vulnerability: CVE-2023-51384 and CVE-2023-51385 on VMware vCenter Server
book
Article ID: 370007
calendar_today
Updated On:
Products
VMware vCenter Server
Issue/Introduction
Vulnerability scanners detect the following OpenSSH vulnerabilities in the environment:
CVE-2023-51384: Priority Medium (CVSS 5.5)
CVE-2023-51385: Priority Medium (CVSS 5.5)
Environment
VMware vCenter Server 7.x
VMware vCenter Server 8.x
Resolution
These vulnerabilities are resolved in the following releases:
vCenter Server 8.x: Resolved in vCenter 8.0 U3.
vCenter Server 7.x:
CVE-2023-51384: Not applicable. This vulnerability affects OpenSSH version 8.9 and above; vCenter 7.x utilizes OpenSSH 7.8p1.
CVE-2023-51385: Resolved in vCenter 7.0 U3v.
Additional Information
Since OpenSSH is one of the packages which comes as a complete installation bundle with VMware vCenter Server we cannot upgrade it to specific version.
Keep SSH disabled on your host unless it is required for troubleshooting purpose
This CVE is affected to the OpenSSH version 8.9 and above
Run the following command on the vCenter SSH to verify the version being used in the environment.
rpm -qa | grep -i ssh
CVE-2023-51384 and CVE- 2023-51385 vulnerabilities are fixed in OpenSSH 8.9p1-6, which are the makeup of VCSA 8.0.3.00000 (8.0 U3).
There should be no impact from CVE-2023-51384 and CVE- 2023-51385 on VCSA 8.0 U3.
If security scanner still reporting them then are false positives.