tgoop.com/sysadmin24x7/5692
Create:
Last Update:
Last Update:
VMSA-2024-0003
CVSSv3 Range: 9.6 - 7.8
Issue Date: 2024-02-20
CVE(s): CVE-2024-22245, CVE-2024-22250
Synopsis:
Addressing Arbitrary Authentication Relay and Session Hijack Vulnerabilities in Deprecated VMware Enhanced Authentication Plug-in (EAP) (CVE-2024-22245, CVE-2024-22250)
Impacted Products
VMware Enhanced Authentication Plug-in (EAP)
Introduction
Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) were responsibly reported to VMware. Guidance is available on removing this deprecated component from impacted environments.
https://www.vmware.com/security/advisories/VMSA-2024-0003.html
BY SysAdmin 24x7
Share with your friend now:
tgoop.com/sysadmin24x7/5692