ZeroHour
Security Affairspublished ()ingested @securityaffairs

VMware fixes CVE-2020

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3952
Authentication Bypass in VMware vCenter Server 6.7 vmdir (CVE-2020-3952)

CVE-2020-3952 is a critical missing-authentication flaw (CWE-306, CVSS 9.8) in vmdir, the VMware Directory Service that ships with vCenter Server as part of an embedded or external Platform Services Controller (PSC). Under certain conditions, vmdir does not correctly implement access controls, so an unauthenticated attacker with network access to the directory service (LDAP) can retrieve directory data without valid credentials. Because that directory data includes vCenter Single Sign-On account information such as credential material, public proof-of-concept content treats the bug as an authentication bypass that can lead to full privileged access to vCenter. Any organization running VMware vCenter Server 6.7 with an embedded or external PSC is affected. Exploitation is confirmed: the flaw was added to CISA's KEV on 2021-11-03, and EPSS assigns a 90.4% probability of exploitation within 30 days (ransomware linkage: unknown).

Do: Upgrade vCenter Server 6.7 to the patched release from VMware (the fix shipped in the 6.7 U3l update per VMware advisory VMSA-2020-0004; apply updates per vendor instructions as required by the KEV listing). Until patched, restrict untrusted network access to vmdir's LDAP service (TCP 389/636) on embedded/external PSCs and review directory logs for unauthenticated access. Inventory whether each vCenter deployment uses an embedded or external PSC, since both topologies are affected.

9.890% KEV PoC
  • vmware vCenter Server (vmdir, via embedded or external Platform Services Controller) 6.7 (version referenced in the public PoC; CISA lists the affected product as 'VMware vCenter Server' without explicit version ranges - apply the vendor's fixed
largetens of thousands of internet-exposed vCenter Servers (~60,000+ observed in public scans at the time), with hundreds of thousands of deployments worldwide…
CVE-2020-3956
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to

VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.

NVD description · AI analysis pending
8.821% PoC ×3
  • vmware vcloud director
Full article325 words · extracted from securityaffairs.com · click to collapse

VMware has addressed a high-severity remote code execution vulnerability, tracked as CVE-2020-3956, that affects its Cloud Director product.

VMware has patched a high-severity remote code execution vulnerability, tracked as CVE-2020-3956, in its Cloud Director product.

The vulnerability is a code injection issue that could be exploited by an authenticated attacker to send malicious traffic to Cloud Director, which could allow executing arbitrary code.

“A code injection vulnerability in VMware Cloud Director was privately reported to VMware. Patches and workarounds are available to remediate or workaround this vulnerability in affected VMware products.” reads the security advisory published by VMware.

“An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.”

According to the company, the vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.

The vulnerability impacts VMware Cloud Director 10.0.x, 9.7.x and 9.5.x on Linux and Photon OS appliances, and version 9.1.x on Linux. Versions 8.x, 9.0.x and 10.1.0 are not affected.

VMware vCloud Director 9.1.0.4, 9.5.0.6, 9.7.0.5 and 10.0.0.2 addresses the issue. VMware has also released a workaround to mitigate the risk of attacks exploiting the issue.

The vulnerability was discovered by Tomáš Melicher and Lukáš Václavík of Citadelo.

A couple of weeks ago, VMware addressed vulnerabilities impacting the vRealize Operations Manager (vROps) product, including two recently disclosed Salt issues.

Earlier this month, VMware has addressed a critical information disclosure flaw, tracked as CVE-2020-3952, that could be exploited by attackers to compromise vCenter Server or other services that use the Directory Service (vmdir) for authentication.

The CVE-2020-3952 vulnerability has received a CVSSv3 score of 10, it resides in the vCenter Server version 6.7 on Windows and virtual appliances.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – CVE-2020-3956, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/103538/security/cve-2020-3956-vmware.html