Junglewise Threat Intelligence

CVE-2020-3952: VMware vCenter Server Information Disclosure Vulnerability

CVE-2020-3952 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: VMware.

Executive brief

VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) due to improper access control implementation in the Platform Services Controller (PSC). An unauthenticated attacker with network access to port 389 can exploit this to extract sensitive information or potentially achieve authentication bypass.

Affected products

  • VMware vCenter Server 6.7

Timeline

  • 2020-04-10: disclosed: Initial NVD publication and VMware advisory VMSA-2020-0006
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV entry