9.1
CVE-2020-4006
- EPSS 17.3%
- Veröffentlicht 23.11.2020 22:15:12
- Zuletzt bearbeitet 30.10.2025 20:07:02
- Erkennungen
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Identity Manager Version 3.3.1
VMware ≫ Identity Manager Version 3.3.2
VMware ≫ Identity Manager Version 3.3.3
VMware ≫ Identity Manager Connector Version 3.3.1
VMware ≫ Identity Manager Connector Version 3.3.2
VMware ≫ One Access Version 20.01
VMware ≫ One Access Version 20.10
VMware ≫ Identity Manager Connector Version 3.3.1
VMware ≫ Identity Manager Connector Version 3.3.2
VMware ≫ Identity Manager Connector Version 3.3.3
VMware ≫ Cloud Foundation Version 4.0
VMware ≫ Cloud Foundation Version 4.0.1
VMware ≫ Vrealize Suite Lifecycle Manager Version >= 8.0 <= 8.2
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Multiple VMware Products Command Injection Vulnerability
SchwachstelleVMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 17.3% | 0.968 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
| NIST | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
| CISA-ADP | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://www.vmware.com/security/advisories/VMSA-2020-0027.html
https://www.kb.cert.org/vuls/id/724367
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-4006