CVE-2024-38814
HIGHVMware HCX >=4.8.0 <4.8.2 - Authenticated SQL Injection and Remote Code Execution
Title source: llmDescription
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager. Updates are available to remediate this vulnerability in affected VMware products.
References (1)
Core 1
Core References
Scores
CVSS v3
8.8
EPSS
0.2553
EPSS Percentile
96.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (2)
vmware/vmware_hcx
4.10.0
vmware/vmware_hcx
4.8.0 - 4.8.2
Published
Oct 16, 2024
Tracked Since
Feb 18, 2026