IDPS signature update for CVE-2024-38812
search cancel

IDPS signature update for CVE-2024-38812

book

Article ID: 410917

calendar_today

Updated On:

Products

VMware vCenter Server VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

Recently, VMware by Broadcom published VMware Security Advisory VMSA-2024-0019 detailing information on vulnerabilities affecting VMware products, which could potentially be exploited by malicious actors. This KB announces 2 Intrusion Detection and Prevention System (IDPS) signatures and provides guidance on how to use them to detect and mitigate potential exploitation attempts of the vulnerability CVE-2024-38812

Environment

VMware vCenter Server 7.0 (before 7.0 U3s), 8.0 (before 8.0 U3b)

Response matrix available in the security advisory for VMSA-2024-0019:
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968

Cause

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution

Resolution

The VMware vDefend IDPS signatures with IDs 113975501 and 113975601 have been developed to detect and mitigate exploitation attempts of the vulnerability CVE-2024-38812.

For information on how to set up Distributed IDS/IPS and Gateway IDS/IPS for VMware vDefend and enable automatic IDPS signature updates, see
NSX 4.2
https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/vdefend/vdefend-atp/4-2/nsx-ids-ips-and-nsx-malware-prevention/nsx-ids-ips-and-nsx-malware-prevention/getting-started-with-nsx-ids-ips-and-nsx-malware-prevention/configuring-nsx-ids-ips-and-nsx-malware-prevention-settings.html
NSX 9.0
https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/vdefend/vdefend-atp/9-0/nsx-ids-ips-and-nsx-malware-prevention.html.

Released IDPS signatures can be viewed in the vDefend Threat Intelligence Service portal:
https://portal.securityti.vmware.com/#/app/ids-signatures