CVE IDAffected SystemVulnerability DescriptionImpactCVE-2023-34048VMware vCenter ServerOut-of-bounds write vulnerability in DCERPC protocol implementation, potentially leading to remote code execution.Enables unauthenticated remote command execution on vulnerable vCenter servers.CVE-2022-41328Fortinet FortiOSPath traversal vulnerability allowing privileged attackers to read/write files via crafted CLI commands.Exploited to download and execute backdoors on FortiGate devices.CVE-2022-22948VMware vCenter ServerInformation disclosure due to improper file permissions, granting access to sensitive data.Used to obtain encrypted credentials from vCenter’s postgresDB for further access.CVE-2023-20867VMware ToolsFailure to authenticate host-to-guest operations, impacting guest VM confidentiality and integrity.Allows unauthenticated Guest Operations from ESXi host to guest virtual machines.CVE-2022-42475Fortinet (unspecified)Vulnerability allowing remote unauthenticated attackers to execute arbitrary code or commands via crafted requests.Enables remote code execution on affected systems.CVE-2025-21590Juniper Networks Junos OSInsufficient system separation in kernel, allowing authenticated local users to insert malicious code.Can lead to full system compromise if shell-level access is gained; limited to Junos OS platforms.
This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 28 Jul 2025 14:55:14 +0000