When performing a Vulnerability Assessment and Penetration Test (VAPT) the test may report security vulnerabilities (CVEs) identified in underlying open-source libraries or components of the Photon OS that VMware product appliances, such as VMware Cloud Director Availability (VCDA) and VMware Cloud Director (VCD), are built upon. Security scans or audits indicate that certain packages within these appliance's operating systems are outdated or contain known vulnerabilities.
Security scanners (such as Tenable Nessus) may report multiple vulnerabilities related to Photon OS 4.0 packages on appliances. Common report details include:
VMware Cloud Director 10.x
VMware Cloud Director Availability 4.7.x
VMware Cloud Director Availability (VCDA) and VMware Cloud Director (VCD) appliances are deployed as pre-configured virtual appliances built on a hardened and customized version of Photon OS. To ensure the stability, compatibility, and integrity of the integrated application, updates to the underlying Photon OS packages (including those addressing CVEs in third-party libraries) are managed and integrated exclusively during the official product release cycle.
Vulnerability remediation for the underlying operating system and bundled components of VMware product appliances is delivered through new, official product releases.
Vulnerability handling adheres to the VMware External Vulnerability Response and Remediation Policy.
You can check the latest VCD and VCDA releases available for download at: