build 7bbbddf7 | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 267 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Postmetadata: name: vmware-security-advisory locale: en labels: author: daniel-stadelmann capability/security: 2.16 vendor/vmware: 0.88 annotations: source: blog-content/posts/en/vmware-security-advisory.md route: /en/insights/vmware-security-advisory/ schema: /nerd/schema/posts.json markdown: /en/insights/vmware-security-advisory.mdspec: title: VMware Security Advisory date: 2024-09-18 author: daniel-stadelmann locale: en summary: >- Broadcom has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0019. The issues are rated 7.5 to 9.8 on the CVSS scale. capabilities: [security] vendors: [vmware] migrated: 2026-08-24 translationReviewed: false draft: false sections: - body: | Broadcom has disclosed a new vulnerability. It is covered by VMware Security Advisory 2024-0019 and the issues are rated 7.5 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be closed with the available update as soon as possible. - heading:

VMSA-2024-0019

body: | The published vulnerability ([CVE-2024-38812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38812)) lets an attacker with network access to the vCenter appliance perform remote code execution. The second one ([CVE-2024-38813](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38813)) lets an attacker with network access to the vCenter appliance obtain root rights through privilege escalation. Only vCenter is affected. Further detail and the fixed version are at [Broadcom](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968). Broadcom reports no known attacks so far. With the vulnerabilities now published that can change within hours. Both soulTec and Broadcom recommend patching the affected systems immediately. If you need a hand, [we are glad to help](https://soultec.ch/contact-us/).status: corpus: 267 alsoLike: - {ref: posts/vmware-security-advisory-vmsa-2024-0012, score: 1.00} - {ref: posts/vmware-security-advisory-vmsa-2022-0030, score: 1.00} - {ref: solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance, score: 0.73}
{ "apiVersion": "soultec.ch/v1", "kind": "Post", "metadata": { "name": "vmware-security-advisory", "locale": "en", "labels": { "author": "daniel-stadelmann", "capability/security": "2.16", "vendor/vmware": "0.88" }, "annotations": { "source": "blog-content/posts/en/vmware-security-advisory.md", "route": "/en/insights/vmware-security-advisory/", "schema": "/nerd/schema/posts.json", "markdown": "/en/insights/vmware-security-advisory.md" } }, "spec": { "title": "VMware Security Advisory", "date": "2024-09-18", "author": "daniel-stadelmann", "locale": "en", "summary": "Broadcom has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0019. The issues are rated 7.5 to 9.8 on the CVSS scale.", "capabilities": [ "security" ], "vendors": [ "vmware" ], "migrated": "2026-08-24", "translationReviewed": false, "draft": false }, "sections": [ { "body": "Broadcom has disclosed a new vulnerability. It is covered by VMware Security Advisory 2024-0019 and the issues are rated 7.5 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be closed with the available update as soon as possible." }, { "heading": "

VMSA-2024-0019

",
"body": "The published vulnerability ([CVE-2024-38812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38812)) lets an attacker with network access to the vCenter appliance perform remote code execution. The second one ([CVE-2024-38813](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38813)) lets an attacker with network access to the vCenter appliance obtain root rights through privilege escalation. Only vCenter is affected. Further detail and the fixed version are at [Broadcom](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968).\n\nBroadcom reports no known attacks so far. With the vulnerabilities now published that can change within hours. Both soulTec and Broadcom recommend patching the affected systems immediately. If you need a hand, [we are glad to help](https://soultec.ch/contact-us/)." } ], "status": { "corpus": 267, "alsoLike": [ { "ref": "posts/vmware-security-advisory-vmsa-2024-0012", "score": "1.00" }, { "ref": "posts/vmware-security-advisory-vmsa-2022-0030", "score": "1.00" }, { "ref": "solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance", "score": "0.73" } ] }}
apiVersion = "soultec.ch/v1"kind = "Post"[metadata]name = "vmware-security-advisory"locale = "en"[metadata.labels]author = "daniel-stadelmann""capability/security" = "2.16""vendor/vmware" = "0.88"[metadata.annotations]source = "blog-content/posts/en/vmware-security-advisory.md"route = "/en/insights/vmware-security-advisory/"schema = "/nerd/schema/posts.json"markdown = "/en/insights/vmware-security-advisory.md"[spec]title = "VMware Security Advisory"date = 2024-09-18author = "daniel-stadelmann"locale = "en"summary = "Broadcom has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0019. The issues are rated 7.5 to 9.8 on the CVSS scale."capabilities = ["security"]vendors = ["vmware"]migrated = 2026-08-24translationReviewed = falsedraft = false[[sections]]body = "Broadcom has disclosed a new vulnerability. It is covered by VMware Security Advisory 2024-0019 and the issues are rated 7.5 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be closed with the available update as soon as possible."[[sections]]heading = "

VMSA-2024-0019

"
body = '''The published vulnerability ([CVE-2024-38812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38812)) lets an attacker with network access to the vCenter appliance perform remote code execution. The second one ([CVE-2024-38813](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38813)) lets an attacker with network access to the vCenter appliance obtain root rights through privilege escalation. Only vCenter is affected. Further detail and the fixed version are at [Broadcom](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968).Broadcom reports no known attacks so far. With the vulnerabilities now published that can change within hours. Both soulTec and Broadcom recommend patching the affected systems immediately. If you need a hand, [we are glad to help](https://soultec.ch/contact-us/).'''[status]corpus = 267[[status.alsoLike]]ref = "posts/vmware-security-advisory-vmsa-2024-0012"score = "1.00"[[status.alsoLike]]ref = "posts/vmware-security-advisory-vmsa-2022-0030"score = "1.00"[[status.alsoLike]]ref = "solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance"score = "0.73"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Post"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>vmware-security-advisory</name> <locale>en</locale> <labels> <author>daniel-stadelmann</author> <entry key="capability/security">2.16</entry> <entry key="vendor/vmware">0.88</entry> </labels> <annotations> <source>blog-content/posts/en/vmware-security-advisory.md</source> <route>/en/insights/vmware-security-advisory/</route> <schema>/nerd/schema/posts.json</schema> <markdown>/en/insights/vmware-security-advisory.md</markdown> </annotations> </metadata> <spec> <title>VMware Security Advisory</title> <date>2024-09-18</date> <author>daniel-stadelmann</author> <locale>en</locale> <summary>Broadcom has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0019. The issues are rated 7.5 to 9.8 on the CVSS scale.</summary> <capabilities> <item>security</item> </capabilities> <vendors> <item>vmware</item> </vendors> <migrated>2026-08-24</migrated> <translationReviewed>false</translationReviewed> <draft>false</draft> </spec> <sections> <section> <body>Broadcom has disclosed a new vulnerability. It is covered by VMware Security Advisory 2024-0019 and the issues are rated 7.5 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be closed with the available update as soon as possible.</body> </section> <section> <heading>

VMSA-2024-0019

</heading>
<body>The published vulnerability ([CVE-2024-38812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38812)) lets an attacker with network access to the vCenter appliance perform remote code execution. The second one ([CVE-2024-38813](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38813)) lets an attacker with network access to the vCenter appliance obtain root rights through privilege escalation. Only vCenter is affected. Further detail and the fixed version are at [Broadcom](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968).Broadcom reports no known attacks so far. With the vulnerabilities now published that can change within hours. Both soulTec and Broadcom recommend patching the affected systems immediately. If you need a hand, [we are glad to help](https://soultec.ch/contact-us/). </body> </section> </sections> <status> <corpus>267</corpus> <alsoLike> <item> <ref>posts/vmware-security-advisory-vmsa-2024-0012</ref> <score>1.00</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2022-0030</ref> <score>1.00</score> </item> <item> <ref>solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance</ref> <score>0.73</score> </item> </alsoLike> </status></manifest>
Post · 2024-09-18

VMware Security Advisory

Broadcom has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0019. The issues are rated 7.5 to 9.8 on the CVSS scale.

2024-09-18Date
Daniel StadelmannAuthor
1Min read
Topics Security 2.16
Vendors VMware 0.88

Broadcom has disclosed a new vulnerability. It is covered by VMware Security Advisory 2024-0019 and the issues are rated 7.5 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be closed with the available update as soon as possible.

VMSA-2024-0019

The published vulnerability (CVE-2024-38812) lets an attacker with network access to the vCenter appliance perform remote code execution. The second one (CVE-2024-38813) lets an attacker with network access to the vCenter appliance obtain root rights through privilege escalation. Only vCenter is affected. Further detail and the fixed version are at Broadcom.

Broadcom reports no known attacks so far. With the vulnerabilities now published that can change within hours. Both soulTec and Broadcom recommend patching the affected systems immediately. If you need a hand, we are glad to help.

You might also like

post 1.00

VMware Security Advisory

post 1.00

VMware Security Advisory

solution 0.73

Advanced Cyber Compliance

Page to follow