Rewterz
Rewterz Threat Advisory – ICS: Johnson Controls IQ Vulnerability
July 26, 2023
Rewterz
Rewterz Threat Advisory – Multiple Trend Micro Apex Central Vulnerabilities
July 27, 2023

Rewterz Threat Advisory – CVE-2023-20891 – VMware Tanzu Application Service for VMs and Isolation Segment Vulnerability

Severity

Medium

Analysis Summary

CVE-2023-20891

VMware Tanzu Application Service for VMs and VMware Isolation Segment could allow a remote authenticated attacker to obtain sensitive information, caused by logging credentials in hex encoding in platform system audit logs. A remote attacker could exploit this vulnerability to obtain hex encoded CF API admin credentials and use this information to launch further attacks against the affected system.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2023-20891

Affected Vendors

VMware

Affected Products

  • VMware Tanzu VMware Tanzu Application Service for VMs 4.0
  • VMware Tanzu VMware Tanzu Application Service for VMs 3.0
  • VMware Tanzu Isolation Segment 4.0
  • VMware Tanzu Isolation Segment 3.0

Remediation

Refer to VMware Security Advisory for patch, upgrade or suggested workaround information.

VMware Security Advisory