VMSA-2008-0015 : Updated ESXi and ESX 3.5 packages address critical security issue in openwsman

high Nessus Plugin ID 52010

Synopsis

The remote VMware ESXi host is missing a security-related patch.

Description

a. Updated Openwsman

Openwsman is a system management platform that implements the Web Services Management protocol (WS-Management). It is installed and running by default. It is used in the VMware Management Service Console and in ESXi.

The openwsman 2.0.0 management service on ESX 3.5 and ESXi 3.5 is vulnerable to the following issue found by the SuSE Security-Team :

- Two remote buffer overflows while decoding the HTTP basic authentication header

This vulnerability could potentially be exploited by users without valid login credentials.
Openwsman before 2.0.0 is not vulnerable to this issue. The ESXi 3.5 patch ESXe350-200808201-O-UG updated openwsman to version 2.0.0.
The ESX 3.5 patch ESX350-200808205-UG updated openwsman to version 2.0.0. These patches are installed as part of the ESX and ESXi Upgrade 2 release. The ESX patch can be installed individually.

Version Information and Workaround The following VMware KB articles provide information on how to obtain the version of openwsman in your environment and what a possible workaround for the issue might be.
ESXi 3.5 Refer to the VMware KB article at http://kb.vmware.com/kb/1005818.
ESX 3.5 Refer to the VMware KB article at http://kb.vmware.com/kb/1006878.

Note: This vulnerability can be exploited remotely only if the attacker has access to the service console network.
Security best practices provided by VMware recommend that the service console be isolated from the VM network. Please see http://www.vmware.com/resources/techresources/726 for more information on VMware security best practices.

The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2008-2234 this issue.

Solution

Apply the missing patch.

See Also

http://lists.vmware.com/pipermail/security-announce/2008/000034.html

Plugin Details

Severity: High

ID: 52010

File Name: vmware_VMSA-2008-0015.nasl

Version: 1.18

Type: local

Published: 2/17/2011

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.3

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:vmware:esxi:3.5

Required KB Items: Host/local_checks_enabled, Host/VMware/release, Host/VMware/version

Patch Publication Date: 9/18/2008

Reference Information

CVE: CVE-2008-2234

CWE: 119

IAVB: 2008-B-0064

VMSA: 2008-0015