Rewterz Threat Advisory – ICS: Johnson Controls IQ Vulnerability
July 26, 2023Rewterz Threat Advisory – Multiple Trend Micro Apex Central Vulnerabilities
July 27, 2023Rewterz Threat Advisory – ICS: Johnson Controls IQ Vulnerability
July 26, 2023Rewterz Threat Advisory – Multiple Trend Micro Apex Central Vulnerabilities
July 27, 2023Severity
Medium
Analysis Summary
CVE-2023-20891
VMware Tanzu Application Service for VMs and VMware Isolation Segment could allow a remote authenticated attacker to obtain sensitive information, caused by logging credentials in hex encoding in platform system audit logs. A remote attacker could exploit this vulnerability to obtain hex encoded CF API admin credentials and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2023-20891
Affected Vendors
VMware
Affected Products
- VMware Tanzu VMware Tanzu Application Service for VMs 4.0
- VMware Tanzu VMware Tanzu Application Service for VMs 3.0
- VMware Tanzu Isolation Segment 4.0
- VMware Tanzu Isolation Segment 3.0
Remediation
Refer to VMware Security Advisory for patch, upgrade or suggested workaround information.