GPU VulnDB

Database/Kernel, userspace & hypervisor

VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisor

CVSS 9.8CVE-2020-3992Kernel, userspace & hypervisorKnown exploitedcurated

Impact

Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisor [KEV]

Who can reach it

Unauthenticated network on the management segment

What to do

Patch and disable the SLP service entirely (VMware's own recommendation). Any ESXi with 427 reachable should be treated as already compromised

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.