CVE-2025-61984 and CVE-2025-61985 (OpenSSH < 10.1 / 10.1p1 RCE) identified on an environment running ESXi 8.0 Update 3e and vCenter Server 8.0 Update 3g
The scan tool recommends upgrading OpenSSH to version 10.1 or later. This document addresses whether this vulnerability affects ESXi and vCenter, and outlines the appropriate remediation path. The finding is related to a vulnerability scan, not a functional service impact.
Both CVEs are client-side vulnerabilities that require the use of the "ProxyCommand" directive in the SSH client configuration to be exploitable.
vSphere 8.x
Security findings can be submitted for formal review through: Broadcom Support