Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Severity (CVSS)

Base score9.8
SeverityCritical
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Provided byCNA

Weaknesses

  • CWE-22 — CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected products

VendorProductVersions
VMwareCloud Foundation9.1.x.x; 9.0.x.x; 5.x
VMwarevSphere Foundation9.1.x.x; 9.0.x.x
VMwarevCenter9.1.x.x to <9.1.0.0300; 9.0.x.x to <9.0.2.0100; 8.0 to <8.0 U3k
VMwareTelco Cloud Infrastructure3.0
VMwareTelco Cloud Platform5.1.x; 5.0.x; 4.x; 3.0

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 31 Jul 2026 07:05 UTC.