CVE-2020-3952
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- VMware vCenter Server Information Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 90% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-306
מוצרים מושפעים
vmware: vcenter server
קישורים
- https://www.vmware.com/security/advisories/VMSA-2020-0006 Broken LinkVendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2020-0006 Broken LinkVendor Advisory
- http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authenti… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authenti… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource