PT-2020-2027 · Vmware · Vmware Vcenter Server+3
Published
2020-04-09
·
Updated
2025-10-30
·
CVE-2020-3952
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware vCenter Server versions prior to the fixed version
Description
The issue is related to insufficient access control in the VMware Directory Service (vmdir) of VMware vCenter Server. This can allow a remote attacker to elevate their privileges. The problem occurs because vmdir does not correctly implement access controls under certain conditions.
Recommendations
For versions prior to the fixed version, consider disabling the vulnerable vmdir service until a patch is available. Restrict access to the Platform Services Controller (PSC) to minimize the risk of exploitation. Avoid using the vulnerable vmdir functionality in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Platform Services Controller
Vmware Vcenter
Vmware Directory Service
Vmware Vcenter Server