CVE-2023-34060

Description

VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . This bypass is not present on port 443 (VCD provider and tenant login). On a new installation of VMware Cloud Director Appliance 10.5, the bypass is not present. VMware Cloud Director Appliance is impacted since it uses an affected version of sssd from the underlying Photon OS. The sssd issue is no longer present in versions of Photon OS that ship with sssd-2.8.1-11 or higher (Photon OS 3) or sssd-2.8.2-9 or higher (Photon OS 4 and 5).

Category

9.8
CVSS
Severity: Critical
CVSS 3.1 •
EPSS 0.09%
Vendor Advisory github.com Vendor Advisory github.com Vendor Advisory github.com Vendor Advisory vmware.com
Affected: n/a VMware Cloud Director Appliance (VCD Appliance)
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-34060?
CVE-2023-34060 has been scored as a critical severity vulnerability.
How to fix CVE-2023-34060?
To fix CVE-2023-34060, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2023-34060 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-34060 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-34060?
CVE-2023-34060 affects n/a VMware Cloud Director Appliance (VCD Appliance).
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.