Aria Operations USB controller report for Critical Severity VMSA-2024-0006

Yesterday VMware released VMSA 2024 0006 that impact all VMs that have configured an USB controller. Matrix response give us two choice: install ESXi patch or apply a workarounds that consist to remove the USB controller from a VMware ESXi virtual machine. If you decide to use the second option I created a report on Aria Operation to determinate which VMs are impacted. 

Below few simple steps to setup the report:

1 - Firs of all you must enable "Disconnected USB controller" properties, in Configure -> Policies -> Policy definitions:


2 - Choose your "Active" policy and click on "edit policy"


3 - Click on "Metrics and Properties"



4 - Search "USB" in virtual machine object type and activate the properties


5 - Create or edit a view adding the "Disconnected USB controller"


6 - Create or edit a report based on the previous view

7 - Filter the column by "false"

Now you have the VMs list affected where you must to remove the USB controller. 

Pay attention: please ensure that the USB controller is not in-use prior to removing it from the virtual machine and this workarounds not fix CVE-2024-22254.

Here some helpful links:
https://www.vmware.com/security/advisories/VMSA-2024-0006.html
https://kb.vmware.com/s/article/87617


Thanks for reading!

Commenti

Post popolari in questo blog

Aria Operations unable to edit credentials

Aria Operations for Logs - Increase datastore alert