« Volver al listado

CVE-2020-3993

Estado: ModificadaMedia (5.9)—

VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-3993",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "VMware NSX-T",
          "versions": [
            {
              "status": "affected",
              "version": "VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-10-20T17:15:12.903",
  "references": [
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2020-0023.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2020-0023.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node."
    },
    {
      "lang": "es",
      "value": "VMware NSX-T (versiones 3.x anteriores 3.0.2, versiones 2.5.x anteriores a 2.5.2.2.0), contiene una vulnerabilidad de seguridad que se presenta en la manera en que permite que un host KVM descargue e instale paquetes desde el administrador de NSX. Un actor malicioso con posicionamiento MITM puede ser capaz de explotar este problema para comprometer el nodo de transporte"
    }
  ],
  "lastModified": "2026-06-17T03:19:23.777",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:vmware_nsx-t_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBDCF754-3AC8-4668-84CB-952DBDD13888",
              "versionEndExcluding": "2.5.2.2.0",
              "versionStartIncluding": "2.5.0"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:vmware_nsx-t_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DD60B7F-6A04-436D-93EA-DC96ED89251B",
              "versionEndExcluding": "3.0.2",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A62C8589-3F25-4652-8CAA-EC10C64C2FF8",
              "versionEndExcluding": "3.10.1.1",
              "versionStartIncluding": "3.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2A68886-4079-4BE1-9E51-6022ED680B86",
              "versionEndExcluding": "4.1",
              "versionStartIncluding": "4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}