ESXi host (Mobility Agent) deployed by HCX is identified as an older version of ESXi
search cancel

ESXi host (Mobility Agent) deployed by HCX is identified as an older version of ESXi

book

Article ID: 394030

calendar_today

Updated On:

Products

VMware HCX VMware vSphere ESX 8.x

Issue/Introduction

The ESXi host (Mobility Agent) that is deployed by HCX will match the oldest version of ESXi host that is contained within the environment.  This is expected behavior as it will ensure compatibility with that host for migration purposes.

Note: The Mobility Agent (MA) host's build number will not match the ESXi's build numbers. It will only match the ESXi version number. For example: If you have an environment running ESXi 8.0.3, the MA will match the 8.0.3 (the lowest version on the environment). However, the build number won't be the same; there is a special build number for the MA host (e.g: 24416880).

It can also result in the behavior where vulnerability scanners will detecting HCX Mobility Agent is running an unpatched version of ESXi (Version less then ESXi80U3d-24585383).

Security Advisory: VMSA-2025-0004: VMware ESXi, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226)

 

Environment

HCX 4.X

Cause

The deployed ESXi host referred to as a Mobility Agent is used exclusively for vMotion, Cold, and Replicated Assisted vMotion (RAV) migrations and is enabled within the HCX manager whenever an IX appliance is deployed.  The version of the ESXi host is determined by the vCenter version and oldest ESXi build version within its inventory.  The version of ESXi deployed from vCenter may not technically be a patched version of ESXi and is identified by the vulnerability scanner as vulnerable.

Resolution

The Mobility Agent ESXi host version is not automatically updated when the vCenter server is updated.  In order to update the Mobility Agent version, the ESXi host will need to be redeployed by using the following procedure

Note: Make sure there are no ongoing migrations in HCX.

  1. Login to HCX Hybridity UI and redeploy IX appliance. This will deploy a new Mobility Agent host matching the vCenter version.
    • From HCX Manager UI -> Interconnect -> Service Mesh >> Appliances >> 'Select-IX-Appliance' >> REDEPLOY

 

Additional Information

The ESXi that appears in the VC when vMotion is enabled within a HCX manager is a "fake" ESXi. From security perspective, HCX will never be vulnerable to ESXi vulnerabilities since no real ESXi is shipped in the appliance. Please refer to VMware Cloud: Introduction to HCX for further details.