CVE Vulnerabilities

CVE-2023-20900

Authentication Bypass by Capture-replay

Published: Aug 31, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 IMPORTANT
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

Weakness

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Affected Software

Name Vendor Start Version End Version
Tools Vmware 10.3.0 (including) 12.3.0 (excluding)
Red Hat Enterprise Linux 7 RedHat open-vm-tools-0:11.0.5-3.el7_9.7 *
Red Hat Enterprise Linux 7.7 Advanced Update Support RedHat open-vm-tools-0:10.3.0-2.el7_7.3 *
Red Hat Enterprise Linux 8 RedHat open-vm-tools-0:12.1.5-2.el8_8.3 *
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions RedHat open-vm-tools-0:10.3.10-3.el8_1.4 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat open-vm-tools-0:11.0.0-4.el8_2.3 *
Red Hat Enterprise Linux 8.2 Telecommunications Update Service RedHat open-vm-tools-0:11.0.0-4.el8_2.3 *
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions RedHat open-vm-tools-0:11.0.0-4.el8_2.3 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat open-vm-tools-0:11.2.0-2.el8_4.3 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat open-vm-tools-0:11.2.0-2.el8_4.3 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat open-vm-tools-0:11.2.0-2.el8_4.3 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat open-vm-tools-0:11.3.5-1.el8_6.4 *
Red Hat Enterprise Linux 9 RedHat open-vm-tools-0:12.1.5-1.el9_2.3 *
Red Hat Enterprise Linux 9.0 Extended Update Support RedHat open-vm-tools-0:11.3.5-1.el9_0.4 *
Open-vm-tools Ubuntu bionic *
Open-vm-tools Ubuntu devel *
Open-vm-tools Ubuntu esm-infra/bionic *
Open-vm-tools Ubuntu esm-infra/xenial *
Open-vm-tools Ubuntu focal *
Open-vm-tools Ubuntu jammy *
Open-vm-tools Ubuntu lunar *
Open-vm-tools Ubuntu mantic *
Open-vm-tools Ubuntu trusty *
Open-vm-tools Ubuntu upstream *
Open-vm-tools Ubuntu xenial *

Potential Mitigations

References