nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-38818 CVE-2024-38818
MEDIUM
Record summary
CVE-2024-38818 has a selected CVSS score of 6.7 (medium).
Description
VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
VMware NSX, VMware Cloud FoundationDefault status: unaffected | CVE List | VMware NSX 4.x, VMware Cloud Foundation 5.x | affected |
cloud_foundationBrowse vmware / cloud_foundationDefault status: unknown | CVE List | 5.0 to < Async_Patch_to_4.2.1 | affected |
Default status: unknown | CVE List | 4.1.0 to < 4.2.1 | affected |
Default status: unknown | CVE List | 3.2.0 to < 3.2.4.1 | affected |
References
2support.broadcom.com
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25047