Workload misconfigurations

VMware Virtual Machine with unauthorized connection of devices enabled

Platform(s)
  • N/A

Compliance Frameworks

Description

A VMware virtual machine is a software-based emulation of a physical computer. Users and processes with privileges on a virtual machine can connect or disconnect hardware devices, any enabled or connected device represents a potential attack channel. An attacker with access to a virtual machine can connect a disconnected hardware device and access sensitive information on media that is left in a hardware device. It was detected that unauthorized connection of devices is enabled.