Locating and downloading CVE Status lists for VCF
search cancel

Locating and downloading CVE Status lists for VCF

book

Article ID: 450429

calendar_today

Updated On:

Products

VMware Cloud Foundation

Issue/Introduction

Customers reviewing vulnerability scan results against VCF infrastructure need access to Broadcom's official Security Vulnerability (CVE) status list to determine whether a flagged CVE status has already been provided. This article explains where to locate and download the Security Vulnerability statuses.

Environment

VCF 9.x
VCF 5.2.x

Resolution

The CVE disposition list is published as a downloadable CSV file under the product entitlement for each supported VCF release. Navigate to the file as follows:

For VCF 9.1:

  1. Log in to the Broadcom Support Portal with an active VCF entitlement.
  2. Select My Downloads from the left hand panel
  3. Select VMware Cloud Foundation.
  4. Select VMware Cloud Foundation 9.
  5. Select version 9.1.0.0.
  6. Select Additional Downloads.
  7. Search for CVE
  8. Agree to the Terms and Conditions
  9. Locate and download the CVE disposition CSV.

For VCF 5.2.x (Legacy VMware Cloud Foundation Versions)

  1. Log in to the Broadcom Support Portal with an active VCF entitlement.
  2. Select My Downloads from the left hand panel
  3. Select VMware Cloud Foundation.
  4. Select Legacy VMware Cloud Foundation Versions.
  5. Select version 5.2.4.0 .
  6. Select Primary Downloads.
  7. Agree to the Terms & Conditions
  8. Locate and download the CVE disposition CSV.

Scope of Status Coverage

Broadcom's disposition review currently focuses on Critical and High severity CVEs. Medium and Low severity CVEs are frequently patched in our Major, Minor and Maintenance releases as part of regular VCF software component lifecycle management, while prioritizing product stability and quality. Support does not individually provide status for these vulnerabilities.   

Scanning Methodology Requirements

Status review and support engagement apply only to findings from scans run at standard/normal sensitivity which identify CVEs of either critical/high/medium:

  • Nessus: Report Paranoia setting of Normal / Avoid False Alarms.
  • Qualys: Detection category of Confirmed Vulnerability.

Note: This policy is applicable to all vulnerability scanners, which must adhere to the recommendations specified above.

Findings surfaced at elevated sensitivity settings (Nessus "Paranoid," Qualys " Potential Vulnerability"), are considered false positives and will not receive disposition commentary from VMware by Broadcom Support.

See KB 414415 for background on why authenticated scanning is not recommended against VCF appliances.

Additional Information

KB 414415 – Authenticated Network Scan of VCF Infrastructure

Minimum Required Versions: 

VCF 5.2.4 — Official Bill of Materials (Core Stack)
VCF CoreCloud Builder VM5.2.425437063
VCF CoreSDDC Manager5.2.425437063
VCF CorevCenter Server Appliance (VCSA)8.0 Update 3j25413364
VCF CoreVMware ESXi8.0 Update 3j25429389
VCF CoreVMware vSAN8.0 Update 3j(bundled in ESXi)
VCF CorevSAN Witness Appliance8.0 Update 3j25429389
VCF CoreVMware NSX4.2.425410638
VCF CoreAria Suite Lifecycle Manager8.18.0 Patch 825425132
Aria Suite — Deployed via Aria Suite Lifecycle 8.18.0 P8
Aria SuiteAria Operations8.18.7 
Aria SuiteAria Operations for Logs8.18.7 
Aria SuiteAria Automation8.18.1 Update 5 
Aria SuiteVMware Identity Manager (vIDM)3.3.7
Adjacent VMware / Broadcom Products — Same Timeframe (Not in VCF BOM)
Live RecoveryVMware Live Recovery Appliance9.0.525103105
Live RecoveryVMware Live Site Recovery9.0.5(bundled in appliance)
Live RecoveryvSphere Replication9.0.5(bundled in appliance)
Live RecoveryvSAN Data Protection9.0.5(bundled in appliance)
Hybrid CloudVMware HCX4.11.525438871 (Connector)
25438872 (Cloud)
Tanzu / vSphere Kubernetes Platform Stack (Optional VCF Add-On)
Tanzu/VKSvSphere Kubernetes Service (VKS)3.4.2+v1.33 
Tanzu/VKSSupported vSphere Kubernetes Releases (VKr)v1.33 
Tanzu/VKSvSphere Supervisor (Workload Management)1.33(embedded in vCenter build 25413364)
TKG StandaloneTanzu Kubernetes Grid (Standalone)2.5.4 
TKG StandaloneTanzu CLIv1.3N/A

Important Note: Customers using 9.0.x versions must upgrade to 9.1, as these releases do not qualify for review.