ZeroHour

CVE-2020-4006

KEVlarge

Command Injection in VMware Workspace ONE Access and Identity Manager

CISA: Multiple VMware Products Command Injection Vulnerability

CVSS 3.1
9.1 critical
EPSS
17%p97
Published
()
KEV added
AI analysis

CVE-2020-4006 is a command injection flaw (CWE-78, CVSS 3.1 9.1) in the admin consoles of VMware Workspace ONE Access, Workspace ONE Access Connector, VMware Identity Manager, and VMware Identity Manager Connector, with the affected components also shipped inside VMware Cloud Foundation and vRealize Suite Lifecycle Manager. An attacker who gains privileged access to an admin console, which is typically reachable over the network, can inject and run arbitrary commands on the appliance, achieving full compromise of the host with high confidentiality, integrity, and availability impact and a changed scope. Organizations running the affected identity products are exposed, especially where the admin console is internet-facing or reachable from untrusted networks. The bug was actively exploited by Russian state-sponsored (SVR/APT29) actors against unpatched deployments, prompting a CISA emergency directive, NSA and FBI joint warnings, and inclusion in the KEV catalog; EPSS estimates a 17.3% probability of exploitation within 30 days, and no public proof-of-concept is known.

What to do: Apply the patches VMware released in its November 2020 advisory (VMSA-2020-0027) for all affected products, connectors, and any Cloud Foundation or vRealize Suite Lifecycle Manager deployments that embed the components — this is a KEV-required action. As an interim mitigation, restrict network access to the admin console (typically port 8443) to trusted users and networks only. Review admin-console and system logs for signs of command injection or SVR/APT29 activity, since the bug was exploited in the wild by Russian state-sponsored actors.

Affected
VMware Workspace ONE Accessmultiple affected releases (3.x/20.x lines) — see VMware security advisory
VMware Workspace ONE Access Connectormultiple affected releases (3.x/20.x lines) — see VMware security advisory
VMware Identity Managermultiple affected releases (3.x/20.x lines) — see VMware security advisory
VMware Identity Manager Connectormultiple affected releases (3.x/20.x lines) — see VMware security advisory
VMware Cloud Foundation (bundles affected Workspace ONE Access/Identity Manager components)affected via bundled components — see VMware security advisory
VMware vRealize Suite Lifecycle Manager (bundles affected Identity Manager components)affected via bundled components — see VMware security advisory
Estimated exposure
largetens of thousands of enterprise identity-appliance deployments, with likely several thousand admin consoles internet-exposed — Workspace ONE Access/Identity Manager are widely deployed enterprise identity products; at disclosure public internet scans showed thousands of exposed admin consoles, and the exploitation was severe enough to trigger a CISA emergency…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

CISA Known Exploited Vulnerability
Affected
VMware Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
identity manager, identity manager connector, one access, cloud foundation, vrealize suite lifecycle manager
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news