Home/VMware (Broadcom)/vCenter Server/vCenter Server 6.0

vCenter Server 6.0

SKU vCenter-Server-6.0

VMware (Broadcom) Os Release · vCenter Server Series

Curated VMware (Broadcom) release notes ↗ Curated from vendor policy · verify against the vendor before acting
vCenter Server 6.0 is dead. VMware (Broadcom) support ended (-2325d).

Is vCenter Server 6.0 still maintained?

No. VMware (Broadcom) no longer maintains vCenter Server 6.0; support ended 2020-03-12. It receives no fixes of any kind, including security patches. Devices running it are unpatched against any newer vulnerability — plan an upgrade to a maintained release. See VMware (Broadcom)'s lifecycle bulletin.

When do security fixes for vCenter Server 6.0 stop?

Engineering fixes for vCenter Server 6.0 — including security patches — stop on 2020-03-12. After that date, a device on this release cannot be patched against newly disclosed vulnerabilities without upgrading, which is the point that matters for KEV exposure and compliance.

What should I upgrade vCenter Server 6.0 to?

Upgrade to a currently maintained VMware (Broadcom) release. Check the release-train table on the vendor page for the nearest supported version.

What known-exploited CVEs apply to the vCenter Server 6.0 past end of support?

10 CVEs in CISA's Known Exploited Vulnerabilities catalog affect VMware (Broadcom) vCenter. Because vCenter Server 6.0 is past end of engineering, it will not receive fixes for them — a device left on this release is exploitable with no patch available. Upgrade to a maintained release. See the Known Exploited Vulnerabilities table below for the full list.

Known Exploited Vulnerabilities

This device is past VMware (Broadcom)'s security-support date. 10 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. VMware (Broadcom) is not issuing patches for this model. Isolate, compensate, or refresh.

CVE KEV added Vulnerability Flags
CVE-2024-38813 VMware vCenter Server Privilege Escalation Vulnerability
CVE-2024-38812 VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
CVE-2022-22948 VMware vCenter Server Incorrect Default File Permissions Vulnerability
CVE-2023-34048 VMware vCenter Server Out-of-Bounds Write Vulnerability
CVE-2021-21973 VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
CVE-2021-22017 VMware vCenter Server Improper Access Control
CVE-2021-22005 VMware vCenter Server File Upload Vulnerability Ransomware
CVE-2020-3952 VMware vCenter Server Information Disclosure Vulnerability
CVE-2021-21972 VMware vCenter Server Remote Code Execution Vulnerability Ransomware
CVE-2021-21985 VMware vCenter Server Improper Input Validation Vulnerability Ransomware

Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.

Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.

vCenter Server 6.0 Release Lifecycle

vCenter Server 6.0 is a VMware (Broadcom) vCenter Server software release. Releases are maintained on a fixed schedule: VMware (Broadcom) ships fixes and security patches until the release reaches end of engineering, after which a device must be upgraded to a maintained release to stay patchable. The dates below are milestones for the software train, not for any specific appliance — hardware running this release has its own separate lifecycle. This product has reached end of life as of , meaning VMware (Broadcom) no longer provides technical support, software updates, or hardware replacement for this product. Organizations still running the vCenter Server 6.0 should plan a migration .

Lifecycle Milestones

Lifecycle notice published 11y 5mo ago
End of software maintenance 6y 4mo ago
End of security vulnerability support 6y 4mo ago
Last date of support 6y 4mo ago

Additional Dates

Ga Date 11y 5mo ago
Applicable Platforms
↑ Top