9.8
CVE-2020-3943
- EPSS 2.33%
- Veröffentlicht 19.02.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:00
- Erkennungen
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Vrealize Operations SwPlatform horizon Version >= 6.6.0 < 6.6.1
VMware ≫ Vrealize Operations SwPlatform horizon Version >= 6.7.0 < 6.7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.33% | 0.813 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
https://www.vmware.com/security/advisories/VMSA-2020-0003.html