Qualys security scanners report the following vulnerabilities on ports 30005 and 30006 of VMSP components, including Fleet Manager and Identity Broker (vIDB):
VMware Cloud Foundation 9.1
The VMSP platform operates a private Public Key Infrastructure (PKI) by design. Certificates on ports 30005 and 30006 are generated and signed by an internal Certificate Authority (vcf-cluster-issuer). External scanners flag the signature verification as failed (QID 38173) and subject common name mismatch (QID 38170) because the internal CA is not present in public or external scanner trust stores. Broadcom Engineering confirmed that ports 30005 (Control Plane Health Check API) and 30006 (Control Plane Webhook API) are utilized strictly for internal operations between the VMSP components and the Platform runtime.
Broadcom Engineering plans to implement a network restriction in future release. Access to these ports will be limited to the VSP management cluster IP Pool. External access will be restricted, preventing external scanners from routing to them and flagging these QIDs.
It is recommended to subscribe to this article to be updated on the fix status. For instructions on how to subscribe, refer to Subscribe to a Broadcom knowledge article by article or product