https://github.com/vmware/photon/wiki/Security-Update-4.0-801.md
Severity: Critical
ID: 236956
File Name: PhotonOS_PHSA-2025-4_0-0801_nodejs.nasl
Version: 1.1
Type: local
Family: PhotonOS Local Security Checks
Published: 5/20/2025
Updated: 5/20/2025
Supported Sensors: Nessus
Risk Factor: Medium
Score: 6.9
Risk Factor: Medium
Base Score: 6.8
Temporal Score: 5.6
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS Score Source: CVE-2018-7160
Risk Factor: Critical
Base Score: 9.8
Temporal Score: 9.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C
CVSS Score Source: CVE-2023-32002
Risk Factor: Critical
Base Score: 9.3
Threat Score: 9.3
Threat Vector: CVSS:4.0/E:A
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score Source: CVE-2023-44487
CPE: p-cpe:/a:vmware:photonos:nodejs, cpe:/o:vmware:photonos:4.0
Required KB Items: Host/local_checks_enabled, Host/PhotonOS/release, Host/PhotonOS/rpm-list
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 5/20/2025
Vulnerability Publication Date: 3/21/2018
CISA Known Exploited Vulnerability Due Dates: 10/31/2023
CVE: CVE-2018-7160, CVE-2022-35255, CVE-2022-35256, CVE-2022-3602, CVE-2022-3786, CVE-2022-43548, CVE-2023-23918, CVE-2023-23919, CVE-2023-23920, CVE-2023-23936, CVE-2023-30581, CVE-2023-30585, CVE-2023-30588, CVE-2023-30589, CVE-2023-30590, CVE-2023-32002, CVE-2023-32006, CVE-2023-32559, CVE-2023-38552, CVE-2023-39333, CVE-2023-44487, CVE-2024-3566, CVE-2025-23083, CVE-2025-23084, CVE-2025-23085