CVE Vulnerabilities

CVE-2023-20867

Improper Authentication

Published: Jun 13, 2023 | Modified: Oct 28, 2025
CVSS 3.x
3.9
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
3.9 LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
ToolsVmware10.3.0 (including)12.2.5 (excluding)
Red Hat Enterprise Linux 7RedHatopen-vm-tools-0:11.0.5-3.el7_9.6*
Red Hat Enterprise Linux 8RedHatopen-vm-tools-0:12.1.5-2.el8_8*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatopen-vm-tools-0:11.0.0-4.el8_2.2*
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceRedHatopen-vm-tools-0:11.0.0-4.el8_2.2*
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsRedHatopen-vm-tools-0:11.0.0-4.el8_2.2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatopen-vm-tools-0:11.2.0-2.el8_4.2*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatopen-vm-tools-0:11.2.0-2.el8_4.2*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatopen-vm-tools-0:11.2.0-2.el8_4.2*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatopen-vm-tools-0:11.3.5-1.el8_6.2*
Red Hat Enterprise Linux 9RedHatopen-vm-tools-0:12.1.5-1.el9_2.1*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatopen-vm-tools-0:11.3.5-1.el9_0.2*
Open-vm-toolsUbuntubionic*
Open-vm-toolsUbuntuesm-infra/bionic*
Open-vm-toolsUbuntuesm-infra/focal*
Open-vm-toolsUbuntuesm-infra/xenial*
Open-vm-toolsUbuntufocal*
Open-vm-toolsUbuntujammy*
Open-vm-toolsUbuntukinetic*
Open-vm-toolsUbuntulunar*
Open-vm-toolsUbuntutrusty*
Open-vm-toolsUbuntuxenial*

Potential Mitigations

References