Customers reviewing vulnerability scan results against VCF infrastructure need access to Broadcom's official Security Vulnerability (CVE) status list to determine whether a flagged CVE status has already been provided. This article explains where to locate and download the Security Vulnerability statuses.
VCF 9.x
VCF 5.2.x
The CVE disposition list is published as a downloadable CSV file under the product entitlement for each supported VCF release. Navigate to the file as follows:
For VCF 9.1:
For VCF 5.2.x (Legacy VMware Cloud Foundation Versions)
Scope of Status Coverage
Broadcom's disposition review currently focuses on Critical and High severity CVEs. Medium and Low severity CVEs are frequently patched in our Major, Minor and Maintenance releases as part of regular VCF software component lifecycle management, while prioritizing product stability and quality. Support does not individually provide status for these vulnerabilities.
Scanning Methodology Requirements
Status review and support engagement apply only to findings from scans run at standard/normal sensitivity which identify CVEs of either critical/high/medium:
Note: This policy is applicable to all vulnerability scanners, which must adhere to the recommendations specified above.
Findings surfaced at elevated sensitivity settings (Nessus "Paranoid," Qualys " Potential Vulnerability"), are considered false positives and will not receive disposition commentary from VMware by Broadcom Support.
See KB 414415 for background on why authenticated scanning is not recommended against VCF appliances.
Important Note: Customers using 9.0.x versions must upgrade to 9.1, as these releases do not qualify for review.