← Vulnerability feed

Vulnerability record · CVE-2023-27312 · published 12 October 2023

CVE-2023-27312: Netapp snapcenter plug-in execution with unnecessary privileges vulnerability

NNetapp · Snapcenter Plug In

SnapCenter Plugin for VMware vSphere versions 4.6 prior to 4.9 are susceptible to a vulnerability which may allow authenticated unprivileged users to modify email and snapshot name settings within the VMware vSphere user interface.

4.3 CVSS 3.1 Medium EPSS 0.36% · top 72.5% CWE-250 · Execution with unnecessary privileges
4.3CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SnapCenter Plugin for VMware vSphere versions 4.6 prior to 4.9 are susceptible to a vulnerability which may allow authenticated unprivileged users to modify email and snapshot name settings within the VMware vSphere user interface.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27312 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2019-10219Redhat hibernate validator cross-site scripting vulnerabilityA vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially mal…EPSS 2.2%5.3CVE-2021-34429Eclipse Jetty URI encoding flaw exposes WEB-INF and bypasses security constraintsEclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 and 11.0.1-11.0.5 mishandle certain encoded characters in URIs, allowing crafted requests to reac…EPSS 99%analysed5.3CVE-2021-28164Eclipse Jetty URI normalization flaw exposes WEB-INF filesEclipse Jetty 9.4.37.v20210219 through 9.4.38.v20210224 in default compliance mode accepts request URIs containing %2e or %2e%2e segments, letting th…EPSS 82%analysed2.7CVE-2021-28163Eclipse jetty information exposure vulnerabilityIn Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the cont…EPSS 4.2%6.6CVE-2025-40602SonicWall SMA1000 management console missing authorization privilege escalationThe SonicWall SMA1000 appliance management console (AMC) contains a local privilege escalation flaw caused by insufficient authorization, mapped to C…KEVEPSS 2.8%analysed9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed

Source: NIST National Vulnerability Database (record CVE-2023-27312), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.