CVE-2020-4006
KEVlargeCommand Injection in VMware Workspace ONE Access and Identity Manager
CISA: Multiple VMware Products Command Injection Vulnerability
CVE-2020-4006 is a command injection flaw (CWE-78, CVSS 3.1 9.1) in the admin consoles of VMware Workspace ONE Access, Workspace ONE Access Connector, VMware Identity Manager, and VMware Identity Manager Connector, with the affected components also shipped inside VMware Cloud Foundation and vRealize Suite Lifecycle Manager. An attacker who gains privileged access to an admin console, which is typically reachable over the network, can inject and run arbitrary commands on the appliance, achieving full compromise of the host with high confidentiality, integrity, and availability impact and a changed scope. Organizations running the affected identity products are exposed, especially where the admin console is internet-facing or reachable from untrusted networks. The bug was actively exploited by Russian state-sponsored (SVR/APT29) actors against unpatched deployments, prompting a CISA emergency directive, NSA and FBI joint warnings, and inclusion in the KEV catalog; EPSS estimates a 17.3% probability of exploitation within 30 days, and no public proof-of-concept is known.
What to do: Apply the patches VMware released in its November 2020 advisory (VMSA-2020-0027) for all affected products, connectors, and any Cloud Foundation or vRealize Suite Lifecycle Manager deployments that embed the components — this is a KEV-required action. As an interim mitigation, restrict network access to the admin console (typically port 8443) to trusted users and networks only. Review admin-console and system logs for signs of command injection or SVR/APT29 activity, since the bug was exploited in the wild by Russian state-sponsored actors.
| VMware Workspace ONE Access | multiple affected releases (3.x/20.x lines) — see VMware security advisory |
| VMware Workspace ONE Access Connector | multiple affected releases (3.x/20.x lines) — see VMware security advisory |
| VMware Identity Manager | multiple affected releases (3.x/20.x lines) — see VMware security advisory |
| VMware Identity Manager Connector | multiple affected releases (3.x/20.x lines) — see VMware security advisory |
| VMware Cloud Foundation (bundles affected Workspace ONE Access/Identity Manager components) | affected via bundled components — see VMware security advisory |
| VMware vRealize Suite Lifecycle Manager (bundles affected Identity Manager components) | affected via bundled components — see VMware security advisory |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
- Affected
- VMware Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- identity manager, identity manager connector, one access, cloud foundation, vrealize suite lifecycle manager
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H