{
  "threat_severity" : "Low",
  "public_date" : "2023-06-13T00:00:00Z",
  "bugzilla" : {
    "description" : "open-vm-tools: authentication bypass vulnerability in the vgauth module",
    "id" : "2213087",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2213087"
  },
  "cvss3" : {
    "cvss3_base_score" : "3.9",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-287",
  "details" : [ "A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.", "A flaw was found in the open-vm-tools package. An attacker with root access privileges over ESXi may be able to cause an authentication bypass in the vgauth module. This may lead to compromised confidentiality and integrity." ],
  "statement" : "Given the requirement that an attacker must have root access over ESXi to exploit the vulnerability, it is recommended to review access policies based on security best practices.",
  "acknowledgement" : "Red Hat would like to thank Mandiant for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3944",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "open-vm-tools-0:11.0.5-3.el7_9.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3949",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "open-vm-tools-0:12.1.5-2.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Advanced Update Support",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3945",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.2",
    "package" : "open-vm-tools-0:11.0.0-4.el8_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Telecommunications Update Service",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3945",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.2",
    "package" : "open-vm-tools-0:11.0.0-4.el8_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3945",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.2",
    "package" : "open-vm-tools-0:11.0.0-4.el8_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3946",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "open-vm-tools-0:11.2.0-2.el8_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3946",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.4",
    "package" : "open-vm-tools-0:11.2.0-2.el8_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3946",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.4",
    "package" : "open-vm-tools-0:11.2.0-2.el8_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3950",
    "cpe" : "cpe:/a:redhat:rhel_eus:8.6",
    "package" : "open-vm-tools-0:11.3.5-1.el8_6.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3948",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "open-vm-tools-0:12.1.5-1.el9_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Extended Update Support",
    "release_date" : "2023-06-29T00:00:00Z",
    "advisory" : "RHSA-2023:3947",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.0",
    "package" : "open-vm-tools-0:11.3.5-1.el9_0.2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2023-20867\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-20867\nhttps://www.vmware.com/security/advisories/VMSA-2023-0013.html\nhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog" ],
  "csaw" : true,
  "name" : "CVE-2023-20867"
}