CVE-2020-3952
VMware vCenter Server: Information Disclosure
As of , CVE-2020-3952 in VMware vCenter Server is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 3 November 2021
- US federal deadline
- 3 May 2022181 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.90Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
- Public exploit
- 2 Metasploit modules and 1 Exploit-DB entry
- Fix
- No vendor link in CISA's entry
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
CISA's description
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
The CVE record's description, from vmware
- CVE published
- 10 April 2020
- Assigned by
- vmware
- CVSS
- 9.8 Critical (CVSS 3.1, from CISA-ADP)
- CWE-306
- Missing Authentication for Critical Function
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 48535).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: VMware vCenter Server vmdir Authentication Bypassauxiliary module, rank normal
- Metasploit: VMware vCenter Server vmdir Information Disclosureauxiliary module, rank normal
- Exploit-DB: VMware vCenter Server 6.7 - Authentication BypassEDB-ID 48535, 1 June 2020
vCenter Server: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2021-21972Remote Code Execution | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2021-21985Improper Input Validation | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2021-22005File Upload | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2022-22948Incorrect Default File Permissions | VMware vCenter Server | Patch this weekMetasploit module | 0.13 | ||
| CVE-2023-34048Out-of-Bounds Write | VMware vCenter Server | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2024-38812Heap-Based Buffer Overflow | VMware vCenter Server | Patch this weekEPSS 0.55 | 0.55 | ||
| CVE-2021-22017Improper Access Control | VMware vCenter Server | Patch soon | 0.49 | ||
| CVE-2024-38813Privilege Escalation | VMware vCenter Server | Patch soon | 0.17 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org