CVE-2024-22250
------------ On February 20, 2024, Broadcom issued a critical security advisory, VMSA-2024-0003, which addresses security vulnerabilities in the VMware Enhanced Authentication Plugin (EAP). The EAP is an additional feature that can be installed on client workstations to allow seamless login to vSphere's management interfaces and tools. It's important to note that this component is not included by default and is not a part of vCenter Server, ESXi, or Cloud Foundation. The VMSA is the definitive source for information regarding affected products and versions, workarounds, and appropriate patches necessary for maintaining your organization's security. This document serves as a supplementary guide to the advisory, providing self-service information to assist you and your organization in determining an appropriate response.
EPSS 0.35% · 27.5th percentile
Risk Scores
Timeline
- Feb 20, 2024 CVE Published
- Feb 20, 2024 PoC Published
- Feb 20, 2024 PoC Published
- Feb 21, 2024 EPSS Score
- Feb 21, 2024 PoC Published
- Feb 21, 2024 PoC Published
- Feb 21, 2024 PoC Published
- Feb 21, 2024 PoC Published
- Feb 21, 2024 PoC Published
- Feb 25, 2024 PoC Published
- Mar 8, 2024 PoC Published
- Mar 19, 2024 EPSS Score