PatchSiren cyber security CVE debrief
CVE-2023-34048 VMware CVE debrief
CVE-2023-34048 affects VMware vCenter Server and is described as an out-of-bounds write vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-22, with remediation due by 2024-02-12, so affected environments should treat it as a priority issue and follow vendor guidance promptly.
- Vendor
- VMware
- Product
- vCenter Server
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2024-01-22
- Original CVE updated
- 2024-01-22
- Advisory published
- 2024-01-22
- Advisory updated
- 2024-01-22
Who should care
VMware vCenter Server administrators, virtualization and infrastructure teams, vulnerability management teams, and incident responders.
Technical summary
The supplied corpus identifies CVE-2023-34048 as an out-of-bounds write issue in VMware vCenter Server and places it in CISA’s Known Exploited Vulnerabilities catalog. The source metadata points to VMware’s advisory VMSA-2023-0023 and the NVD record for additional official reference, but no CVSS score or exploit narrative is included in the corpus.
Defensive priority
Urgent
Recommended defensive actions
- Apply mitigations per VMware’s vendor instructions as soon as possible.
- If mitigations are unavailable, discontinue use of the product per CISA guidance.
- Prioritize remediation to meet the CISA KEV due date of 2024-02-12.
- Verify which VMware vCenter Server instances are in scope for this CVE.
- Monitor the official CVE, NVD, CISA KEV, and VMware advisory references for updates.
Evidence notes
The supplied source item marks this vulnerability as a CISA KEV entry for VMware vCenter Server, with dateAdded 2024-01-22 and dueDate 2024-02-12. The source metadata explicitly includes the required action to apply vendor mitigations or discontinue use if mitigations are unavailable, and it references VMware advisory VMSA-2023-0023 plus the NVD record. No CVSS score was provided in the supplied corpus.
Official resources
-
CVE-2023-34048 CVE record
CVE.org
-
CVE-2023-34048 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
-
Source item URL
cisa_kev
CVE-2023-34048 was published and modified on 2024-01-22 in the supplied timeline. CISA added it to the KEV catalog the same day, with a due date of 2024-02-12.