Start a Conversation

Unsolved

VM

1 Rookie

 • 

4 Posts

563

August 12th, 2025 07:47

Vxrail Security Update still missing after 28 days / VMSA-2025-0013 CVSS Score > 9

Hi, 

on 15.07.25 Broadcom released some fixed for critical security issues in ESXi. After 28 days there is still no update for VxRail. 
A couple of days ago there was an update showing up in the VxRail plugin in vcenter (8.0.360) but download wasn't possible through vcenter and there was no mentioning nor update package on the dell support pages. Shortly after that the update vanished again in the VxRail plugin. 

When will the update be available? This is a major security risk with the possibility to break out of a vm! 

With this kind of support vxrail is not usable in production environment with sensitive data or critical systems.


I'm relating to this issues:

VMSA-2025-0013: VMware ESXi, Workstation, Fusion, and Tools updates address multiple vulnerabilities (CVE-2025-41236, CVE-2025-41237, CVE-2025-41238, CVE-2025-41239)

kind regards, 

Volker Maibaum

Moderator

 • 

9.3K Posts

August 12th, 2025 14:46

Hi,

 

Thanks for your question.

https://www.dell.com/support/kbdoc/en-us/000343605 covers it

Let us know if you have any additional questions.

1 Rookie

 • 

4 Posts

August 12th, 2025 14:49

@DELL-Josh Cr​ 

Hi Josh, 

I've looked through the article. 

"VxRail Engineering is working on an updated VxRail Software 8.0.3xx release which includes the ESXi build to fix the issue described in VMSA-2025-0013."

Is Dell able to provide an estimated date for the 8.0.3xx release?

Thanks,

Joe

Moderator

 • 

9.3K Posts

August 12th, 2025 15:03

No, we don't give estimates on future updates in case there are delays. 

1 Rookie

 • 

4 Posts

August 12th, 2025 15:18

Hi, 

thanks for your reply. I will then manually patch the esxi hosts.

I still think it's a bit disappointing that Dell is on the one hand supporting this esxi release but isn't pushing the esxi-patch via VxRail (without firmware, etc).
We pay a lot of money for VxRail support to have an easy update mechanism and now I have to fall back to a different manual upgrade procedure. 

We are currently discussing what we will do after our maintenance ends. Not having critical fixes in a timely manner and increasing prices are a strong argument for moving away from VxRail....  

Kind regards, 

Volker

1 Rookie

 • 

12 Posts

August 13th, 2025 13:49

1 Rookie

 • 

4 Posts

August 14th, 2025 06:34

Hi,

I just saw the following in the release notes - I hope this way it will be possible to get security fixes faster:

 

Lifecycle Management:

  • Support for directly applying VMware ESXi Express patch acquired from Broadcom for the fastest security responsiveness using VxRail UI or API. The following are the advantages of applying the VMware ESXi Express patch:
    • Bypasses 14-day SimShip dependency
    • A streamlined experience through VxRail Manager that does not require Support assistance. This provides the upgrade control necessary to address VMware ESXi vulnerabilities when Broadcom releases a VMware ESXi Express patch.

1 Rookie

 • 

4 Posts

August 14th, 2025 08:11

Did 8.0.360 get pulled? As it's not available as a download anymore.

1 Rookie

 • 

12 Posts

August 14th, 2025 08:27

I think it was withdrawn because of this KB. 

https://www.dell.com/support/kbdoc/en-us/000356213

We migrated 8.0.360 to our systems yesterday and didn't have this problem, I hope we won't regret it.

1 Rookie

 • 

4 Posts

August 14th, 2025 08:28

@Omer Faruk​ Thanks Omer, hope it gets fixed fast.

1 Rookie

 • 

4 Posts

August 15th, 2025 08:22

@DELL-Josh Cr​ Hi Josh, Do you have any information on why 8.0.360 got pulled and if we can expect it to be republished anytime soon?

1 Rookie

 • 

4 Posts

August 15th, 2025 08:29

Hi, 

I had a support case open because I had an issue uploading the 8.0.360 package to VxRail.

The support told me that the update was accidently released too early and that the actual release was planned for the 18.08. 

1 Rookie

 • 

2 Posts

August 18th, 2025 19:24

As of August 18, 2025 there still isn't a release...

1 Rookie

 • 

12 Posts

August 18th, 2025 19:55

Hi alan;

CVE details for the new package are given in the Advisories bulletin. I think it should be in the repos in a few hours. We were one of the first to get the package when they released it early. We haven't observed anything abnormal in our cluster, but it still makes me nervous that the package is being withdrawn. Let's see if there will be a change in the release notes.

https://www.dell.com/support/kbdoc/en-us/000358419/dsa-2025-317-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities

1 Rookie

 • 

4 Posts

August 19th, 2025 06:49

From release notes, I think we can wait a bit more for a repost unfortunately.

"VxRail 8.0.360 has been removed from the online support portal. During VCF testing, an issue was identified in the VxRail 8.0.360 bundle that needed to be resolved for VCF support of this VxRail release."

1 Rookie

 • 

1 Message

August 21st, 2025 06:28

Hey, there is a new version 8.0.361 available. Hopefully it will be ok and not removed again 

No Events found!

Top