B&B Bezpieczeństwo w biznesie
  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

Producent oprogramowania do wirtualizacji VMware zaprezentował najnowszą aktualizację dotyczącą produktu VMware ESXi 7.0 Update 3p a w niej wiele poprawek związanych z bezpieczeństwem. Update głównie skupia się na łataniu wykrytych podatności oznaczonych jako CVE-2024-22252, CVE-2024-22253, CVE-2024-22254 i CVE-2024-22255, które dotyczą luki w zabezpieczeniach kontrolera USB XHCI. Wiąże się to z możliwością wykonania kodu jako procesu VMX maszyny wirtualnej działającej na hoście i kilku innych problemów, gdzie osoba niepożądana może wyzwolić zapis poza zakresem i uwolnić zagrożenie z sandboxa. Podatności zaklasyfikowane są jako zagrożenie krytyczne oraz wysokie. Więcej informacji można znaleźć w artykule poniżej.

Znane problemy:

Installation, Upgrade, and Migration Issues

  • The vCenter Upgrade/Migration pre-checks fail with „Unexpected error 87”
  • Corrupted VFAT partitions from a vSphere 6.7 environment might cause upgrades to ESXi 7.x to fail
  • Problems upgrading to vSphere 7.0 with pre-existing CIM providers
  • Installation of 7.0 Update 1 drivers on ESXi 7.0 hosts might fail
  • UEFI booting of ESXi hosts might stop with an error during an update to ESXi 7.0 Update 2 from an earlier version of ESXi 7.0
  • If legacy VIBs are in use on an ESXi host, vSphere Lifecycle Manager cannot extract a desired software specification to seed to a new cluster
  • You see a short burst of log messages in the syslog.log after every ESXi boot
  • You see warning messages for missing VIBs in vSphere Quick Boot compatibility check reports
  • Auto bootstrapping a cluster that you manage with a vSphere Lifecycle Manager image fails with an error
  • Upgrades to ESXi 7.x from 6.5.x and 6.7.0 by using ESXCLI might fail due to a space limitation
  • You cannot migrate linked clones across vCenter Servers
  • Migration across vCenter Servers of virtual machines with many virtual disks and snapshot levels to a datastore on NVMe over TCP storage might fail
  • A virtual machine with enabled Virtual Performance Monitoring Counters (VPMC) might fail to migrate between ESXi hosts
  • If a live VIB install, upgrade, or remove operation immediately precedes an interactive or scripted upgrade to ESXi 7.0 Update 3 by using the installer ISO, the upgrade fails
  • Smart Card and RSA SecurID authentication might stop working after upgrading to vCenter Server 7.0
  • The vlanid property in custom installation scripts might not work
  • HPE servers with Trusted Platform Module (TPM) boot, but remote attestation fails
  • Upgrading a vCenter Server with an external Platform Services Controller from 6.7u3 to 7.0 fails with VMAFD error
  • Smart card and RSA SecurID settings may not be preserved during vCenter Server upgrade
  • Migration of vCenter Server for Windows to vCenter Server appliance 7.0 fails with network error message
  • When you configure the number of virtual functions for an SR-IOV device by using the max_vfs module parameter, the changes might not take effect
  • Upgraded vCenter Server appliance instance does not retain all the secondary networks (NICs) from the source instance
  • After upgrading or migrating a vCenter Server with an external Platform Services Controller, users authenticating using Active Directory lose access to the newly upgraded vCenter Server instance
  • Migrating a vCenter Server for Windows with an external Platform Services Controller using an Oracle database fails
  • After an ESXi host upgrade, a Host Profile compliance check shows non-compliant status while host remediation tasks fail
  • Error message displays in the vCenter Server Management Interface

Security Features Issues

  • Turn off the Service Location Protocol service in ESXi, slpd, to prevent potential security vulnerabilities
  • Encrypted virtual machine fails to power on when HA-enabled Trusted Cluster contains an unattested host
  • Encrypted virtual machine fails to power on when DRS-enabled Trusted Cluster contains an unattested host
  • Migrating or cloning encrypted virtual machines across <span>vCenter Server</span> instances fails when attempting to do so using the vSphere Client

Networking Issues

  • Reduced throughput in networking performance on Intel 82599/X540/X550 NICs
  • One or more I/O devices do not generate interrupts when the AMD IOMMU is in use
  • When you set auto-negotiation on a network adapter, the device might fail
  • Solarflare x2542 and x2541 network adapters configured in 1x100G port mode achieve throughput of up to 70Gbps in a vSphere environment
  • VLAN traffic might fail after a NIC reset
  • Any change in the NetQueue balancer settings causes NetQueue to be disabled after an ESXi host reboot
  • Paravirtual RDMA (PVRDMA) network adapters do not support NSX networking policies
  • Rollback from converged vSphere Distributed Switch (VDS) to NSX-T VDS is not supported in vSphere 7.0 Update 3
  • If you do not set the nmlx5 network driver module parameter, network connectivity or ESXi hosts might fail
  • High throughput virtual machines may experience degradation in network performance when Network I/O Control (NetIOC) is enabled
  • IPv6 traffic fails to pass through VMkernel ports using IPsec
  • Higher ESX network performance with a portion of CPU usage increase
  • VM might lose Ethernet traffic after hot-add, hot-remove or storage vMotion
  • Change of IP address for a VCSA deployed with static IP address requires that you create the DNS records in advance

Więcej informacji o najnowszej aktualizacji można przeczytać w dokumentacji technicznej.

Notatki producenta: VMware ESXi 7.0 Update 3p

Pozdrawiamy,

Zespół B&B
Bezpieczeństwo w biznesie

Post Views: 1 311

esxi 7.0u3p VMware

Poprzedni artykułFortiOS 7.2.8Następny artykuł VMware ESXi 8.0 Update 1d

Najnowsze

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

Kategorie

  • Acronis
  • Aktualności
  • Bez kategorii
  • ESET
  • F-Secure
  • FortiAnalyzer
  • FortiAP
  • FortiAuthenticator
  • FortiClient
  • FortiDeceptor
  • FORTIGATE
  • FORTIMAIL
  • FortiManager
  • FortiNAC
  • FortiSIEM
  • FORTISWITCH
  • FortiWeb
  • NAKIVO
  • Proget
  • Qnap
  • Stormshield
  • Szkolenia
  • Veeam
  • VMware
  • WithSecure

Tagi

6.0.6 6.2.2 6.2.7 6.4.0 6.4.4 6.4.5 6.4.8 7.0.0 7.0.2 7.0.5 7.2.0 7.2.2 ems Eset eset endpoint antivirus eset endpoint security ESET Inspect ESET Protect ESET Protect Cloud F-Secure FMG FortiAnalyzer forti analyzer FortiAP fortiap-w2 FortiAuthenticator FortiClient FortiClientEMS forticlient ems FortiGate FortiMail FortiManager FortiNAC Fortinet FortiOS FortiSIEM FortiSwitch FortiWeb vCenter vCenter Server VMware VMware ESXi vmware esxi 8.0 vmware vcenter VMware vCenter Server

MENU

  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

BLOG TECHNICZNY

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

KONTAKT

biuro@b-and-b.plhttps://www.b-and-b.pl
8:00-16:00
RODO | POLITYKA PRYWATNOŚCI
OGÓLNE WARUNKI REKLAMACJI

BEZPIECZEŃSTWO W BIZNESIE 2025 - wszystkie prawa zastrzeżone

MENU

  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

BLOG TECHNICZNY

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

Kontakt

+48 500-413-313
biuro@b-and-b.pl
8:00-16:00

Korzystamy z plików cookies lub podobnych technologii, by lepiej dopasować treści na stronie do Twoich potrzeb. W każdej chwili możesz zmienić ustawienia cookies. Polityka prywatności

Odmów
Akceptuję
Cookies are small text files that can be used by websites to make a user's experience more efficient. The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission. This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.
  • Necessary
    Always Active
    Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

  • Marketing
    Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

  • Analytics
    Analytics cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

  • Preferences
    Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

  • Unclassified
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.