PT-2021-2235 · Vmware+4 · Vsphere+6

Published

2016-11-21

·

Updated

2024-08-08

·

CVE-2020-28972

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SaltStack Salt versions prior to 3002.5
Description The issue is related to errors in the certificate authentication procedure on vCenter, vSphere, and ESXi servers. This can allow a remote attacker to perform a "man-in-the-middle" attack. The problem lies in the vmware.py files, where authentication to VMware servers does not always validate the SSL/TLS certificate.
Recommendations For versions prior to 3002.5, update to version 3002.5 or later to resolve the issue. As a temporary workaround, consider disabling the vmware.py files until a patch is available. Restrict access to the vulnerable vmware.py module to minimize the risk of exploitation. Avoid using the vulnerable authentication mechanism in the affected API endpoints until the issue is resolved.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2317
ALT-PU-2017-2801
ALT-PU-2018-2416
ALT-PU-2019-2322
ALT-PU-2019-2359
ALT-PU-2021-1590
ALT-PU-2021-1591
ALT-PU-2021-1982
ALT-PU-2022-3218
BDU:2021-01180
CVE-2020-28972
DLA-2815-1
DSA-5011-1
GHSA-W589-R335-4F55
OPENSUSE-SU-2021:0347-1
OPENSUSE-SU-2021_0347-1
PYSEC-2021-74
SUSE-RU-2021:0632-1
SUSE-RU-2021:0633-1
SUSE-SU-2021:0624-1
SUSE-SU-2021:0626-1
SUSE-SU-2021:0627-1
SUSE-SU-2021:0628-1
SUSE-SU-2021:0630-1
SUSE-SU-2021:0631-1
SUSE-SU-2021:0914-1
SUSE-SU-2021:0915-1
SUSE-SU-2021:14650-1
SUSE-SU-2021:1690-1
SUSE-SU-2021_14650-1
SUSE-SU-2021_14682-1
USN-6948-1

Affected Products

Alt Linux
Esxi
Saltstack Salt
Suse
Ubuntu
Vcenter
Vsphere