CVE-2020-3952
KEV PoC largeAuthentication Bypass in VMware vCenter Server 6.7 vmdir (CVE-2020-3952)
CISA: VMware vCenter Server Information Disclosure Vulnerability
CVE-2020-3952 is a critical missing-authentication flaw (CWE-306, CVSS 9.8) in vmdir, the VMware Directory Service that ships with vCenter Server as part of an embedded or external Platform Services Controller (PSC). Under certain conditions, vmdir does not correctly implement access controls, so an unauthenticated attacker with network access to the directory service (LDAP) can retrieve directory data without valid credentials. Because that directory data includes vCenter Single Sign-On account information such as credential material, public proof-of-concept content treats the bug as an authentication bypass that can lead to full privileged access to vCenter. Any organization running VMware vCenter Server 6.7 with an embedded or external PSC is affected. Exploitation is confirmed: the flaw was added to CISA's KEV on 2021-11-03, and EPSS assigns a 90.4% probability of exploitation within 30 days (ransomware linkage: unknown).
What to do: Upgrade vCenter Server 6.7 to the patched release from VMware (the fix shipped in the 6.7 U3l update per VMware advisory VMSA-2020-0004; apply updates per vendor instructions as required by the KEV listing). Until patched, restrict untrusted network access to vmdir's LDAP service (TCP 389/636) on embedded/external PSCs and review directory logs for unauthenticated access. Inventory whether each vCenter deployment uses an embedded or external PSC, since both topologies are affected.
| vmware vCenter Server (vmdir, via embedded or external Platform Services Controller) | 6.7 (version referenced in the public PoC; CISA lists the affected product as 'VMware vCenter Server' without explicit version ranges - apply the vendor's fixed |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
- Affected
- VMware vCenter Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- vcenter server
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H