CVE Vulnerabilities

CVE-2023-20900

Authentication Bypass by Capture-replay

Published: Aug 31, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 IMPORTANT
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

Weakness

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Affected Software

NameVendorStart VersionEnd Version
ToolsVmware10.3.0 (including)12.3.0 (excluding)
Red Hat Enterprise Linux 7RedHatopen-vm-tools-0:11.0.5-3.el7_9.7*
Red Hat Enterprise Linux 7.7 Advanced Update SupportRedHatopen-vm-tools-0:10.3.0-2.el7_7.3*
Red Hat Enterprise Linux 8RedHatopen-vm-tools-0:12.1.5-2.el8_8.3*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatopen-vm-tools-0:10.3.10-3.el8_1.4*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatopen-vm-tools-0:11.0.0-4.el8_2.3*
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceRedHatopen-vm-tools-0:11.0.0-4.el8_2.3*
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsRedHatopen-vm-tools-0:11.0.0-4.el8_2.3*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatopen-vm-tools-0:11.2.0-2.el8_4.3*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatopen-vm-tools-0:11.2.0-2.el8_4.3*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatopen-vm-tools-0:11.2.0-2.el8_4.3*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatopen-vm-tools-0:11.3.5-1.el8_6.4*
Red Hat Enterprise Linux 9RedHatopen-vm-tools-0:12.1.5-1.el9_2.3*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatopen-vm-tools-0:11.3.5-1.el9_0.4*
Open-vm-toolsUbuntubionic*
Open-vm-toolsUbuntudevel*
Open-vm-toolsUbuntuesm-infra/bionic*
Open-vm-toolsUbuntuesm-infra/focal*
Open-vm-toolsUbuntuesm-infra/xenial*
Open-vm-toolsUbuntufocal*
Open-vm-toolsUbuntujammy*
Open-vm-toolsUbuntulunar*
Open-vm-toolsUbuntumantic*
Open-vm-toolsUbuntutrusty*
Open-vm-toolsUbuntuupstream*
Open-vm-toolsUbuntuxenial*

Potential Mitigations

References