ZeroHour

CVE-2020-3952

KEV PoC large

Authentication Bypass in VMware vCenter Server 6.7 vmdir (CVE-2020-3952)

CISA: VMware vCenter Server Information Disclosure Vulnerability

CVSS 3.1
9.8 critical
EPSS
90%p100
Published
()
KEV added
AI analysis

CVE-2020-3952 is a critical missing-authentication flaw (CWE-306, CVSS 9.8) in vmdir, the VMware Directory Service that ships with vCenter Server as part of an embedded or external Platform Services Controller (PSC). Under certain conditions, vmdir does not correctly implement access controls, so an unauthenticated attacker with network access to the directory service (LDAP) can retrieve directory data without valid credentials. Because that directory data includes vCenter Single Sign-On account information such as credential material, public proof-of-concept content treats the bug as an authentication bypass that can lead to full privileged access to vCenter. Any organization running VMware vCenter Server 6.7 with an embedded or external PSC is affected. Exploitation is confirmed: the flaw was added to CISA's KEV on 2021-11-03, and EPSS assigns a 90.4% probability of exploitation within 30 days (ransomware linkage: unknown).

What to do: Upgrade vCenter Server 6.7 to the patched release from VMware (the fix shipped in the 6.7 U3l update per VMware advisory VMSA-2020-0004; apply updates per vendor instructions as required by the KEV listing). Until patched, restrict untrusted network access to vmdir's LDAP service (TCP 389/636) on embedded/external PSCs and review directory logs for unauthenticated access. Inventory whether each vCenter deployment uses an embedded or external PSC, since both topologies are affected.

Affected
vmware vCenter Server (vmdir, via embedded or external Platform Services Controller)6.7 (version referenced in the public PoC; CISA lists the affected product as 'VMware vCenter Server' without explicit version ranges - apply the vendor's fixed
Estimated exposure
largetens of thousands of internet-exposed vCenter Servers (~60,000+ observed in public scans at the time), with hundreds of thousands of deployments worldwide… — Public internet-wide scan data around disclosure time recorded on the order of 60,000+ reachable vCenter instances, and vCenter 6.7 was then the current release broadly deployed across enterprise vSphere estates, so the total install base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

CISA Known Exploited Vulnerability
Affected
VMware vCenter Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
vcenter server
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news