Web Cache Poisoning Denial of Service (CPDOS) Detection on vCenter Server
search cancel

Web Cache Poisoning Denial of Service (CPDOS) Detection on vCenter Server

book

Article ID: 442435

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

You see security scans from tools report a 'Web Cache Poisoning Denial of Service' (CPDOS) vulnerability on vCenter Server 8.0 over port 443.

Environment

vCenter 8.0

Cause

Internal security investigations and applicability assessments confirm that the specific cache poisoning scenario described in these scanner reports cannot be exploited against the vCenter Server architecture. The vulnerability report is non-impacting to the vCenter Server environment.

Resolution

This vulnerability is considered non-impacting and cannot be exploited against vCenter Server; therefore, you do not need to perform any remediation. Engineering and security assessments validate that the exploit mechanics do not apply to the vCenter 8.0 architecture, rendering the system safe from this specific Denial of Service vector.