﻿{"id":745,"date":"2020-04-13T18:29:04","date_gmt":"2020-04-13T23:29:04","guid":{"rendered":"https:\/\/www.uv.mx\/csirt\/?p=745"},"modified":"2020-04-13T18:29:04","modified_gmt":"2020-04-13T23:29:04","slug":"13-04-2020-actualizaciones-de-seguridad-vmware","status":"publish","type":"post","link":"https:\/\/www.uv.mx\/csirt\/boletines\/actualizaciones\/13-04-2020-actualizaciones-de-seguridad-vmware\/","title":{"rendered":"13\/04\/2020 Actualizaciones de seguridad VMware"},"content":{"rendered":"<p>&nbsp;<\/p>\n<div style=\"width: 752px;max-width: 752px;height: auto;border: 1px solid #369;margin: 0px auto;background-color: #fff\">\n<p><img decoding=\"async\" style=\"width: 750px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/boletin-encabezado.jpg\" alt=\"\" \/><\/p>\n<table style=\"width: 100%\" border=\"0\" cellspacing=\"1\" cellpadding=\"1\" align=\"center\">\n<tbody>\n<tr>\n<td><img decoding=\"async\" style=\"width: 144px;height: 25px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/cintillo_critico.jpg\" alt=\"\" \/><\/td>\n<td style=\"text-align: right\"><span style=\"font-size: 18px\"><span style=\"color: #666666\"><span style=\"font-family: tahoma,geneva,sans-serif\">13 de abril de 2020<\/span><\/span><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><strong>Actualizaciones de seguridad VMware <\/strong><\/div>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><span style=\"font-size: 16px\">ID: 13042025<\/span><\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Descripci\u00f3n<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">VMware ha publicado actualizaciones de seguridad corrigiendo varias vulnerabilidades que afectan a su\u00a0producto vCenter Server,con identificador CVE-2020-3952.\u00a0La\u00a0referencia\u00a0apunta\u00a0a\u00a0fallos en el servicio de directorio (vmdir) para la autenticaci\u00f3n, de ser explotado\u00a0por un atacante, podr\u00eda comprometer el servidor de vCenter.<\/p>\n<p style=\"text-align: justify\">De acuerdo con VMware, la vulnerabilidad podr\u00eda ser explotada s\u00f3lo en instalaciones de vCenter Server que hayan sido actualizadas desde una versi\u00f3n anterior. Las instalaciones limpias no se ven afectadas.<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><strong><span style=\"font-size: 16px\">Productos afectados<\/span><\/strong><\/span><\/p>\n<\/div>\n<div style=\"background-color: #c1272d;line-height: 1.4\">\n<p>&nbsp;<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<ul>\n<li>VMware vCenter Server 6.7 Windows\u00a0y Virtual Appliance<\/li>\n<\/ul>\n<hr size=\"2\" \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Soluci\u00f3n:<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">Los administradores de esta soluci\u00f3n pueden determinar si son\u00a0ven afectados si ven en los registros de entrada en <em>vmdir<\/em>, si el servicio comienza a indicar que <em>legacy ACL mode <\/em>est\u00e1\u00a0activado.<\/p>\n<p style=\"text-align: justify\">Para comprobarlo puedes dirigirte a las siguientes rutas:<\/p>\n<p style=\"text-align: justify\"><strong>Virtual Appliance Log File Location:<\/strong> \/var\/log\/vmware\/vmdir\/vmdirrd-syslog.log<\/p>\n<p><strong>Windows Log File Location: <\/strong>%ALLUSERPROFILE%\\VMWare\\vCenterServer\\logs\\vmdir\\vmdir.log<\/p>\n<p>En el siguiente enlace vienen los pasos a seguir para validar si <em>legacy ACL mode<\/em> est\u00e1 activado\u00a0<a href=\"https:\/\/kb.vmware.com\/s\/article\/78543\">https:\/\/kb.vmware.com\/s\/article\/78543<\/a><\/p>\n<p style=\"text-align: justify\">VMware ha solucionado esta vulnerabilidad de vCenter Server actualizando de la versi\u00f3n 6.7 a la versi\u00f3n 7.0 que se encuentra disponible para su descarga en su p\u00e1gina web.<\/p>\n<p><span style=\"font-size: 14px\">Para m\u00e1s informaci\u00f3n:<\/span><\/p>\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0006.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0006.html<\/a><\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<p><img decoding=\"async\" style=\"width: 750px;height: 120px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/cintillo_inferior.jpg\" alt=\"\" \/><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; 13 de abril de 2020 Actualizaciones de seguridad VMware ID: 13042025 Descripci\u00f3n VMware ha publicado actualizaciones de seguridad corrigiendo varias vulnerabilidades que afectan a su\u00a0producto vCenter Server,con identificador CVE-2020-3952.\u00a0La\u00a0referencia\u00a0apunta\u00a0a\u00a0fallos en el servicio de directorio (vmdir) para la autenticaci\u00f3n, de ser explotado\u00a0por un atacante, podr\u00eda comprometer el servidor de vCenter. De acuerdo con VMware, la [&hellip;]<\/p>\n","protected":false},"author":2037,"featured_media":476,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ventana_nueva":"","tipo_url":"","url":"","extracto":"","imagen_halign":"","imagen_valign":"","bg_size":"","text_hide":"","media_url":"","tipo_media":"","video_url":"","video_pos":"","video_youtube":"","footnotes":""},"categories":[8,17],"tags":[],"class_list":["post-745","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actualizaciones","category-criticos"],"_links":{"self":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/users\/2037"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/comments?post=745"}],"version-history":[{"count":0,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/745\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media\/476"}],"wp:attachment":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media?parent=745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/categories?post=745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/tags?post=745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}