Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
This bug CSCwa45730 [Known Fixed Releases] contains 5.0(1c) as fixed. This is incorrect. I opened a Cisco HXDP support case to clarify and indeed, 5.0(1c) is vulnerable. Only HXDP containing ESXi 7.0U3i or later with an upgrade to HXDP 5.0(2a) or later is fixed. I requested that Cisco update the bug [Known Fixed Releases] to address this documentation defect.
Support for ESXi 7.0U3 began to be included with HXDP 5.0(2a). Confusingly the bug report shows 5.0(1c) as also fixed, but 5.0(1c) is at the ESXi 7.0U2 level, so is not fixed.