« Volver al listado

CVE-2020-3994

Estado: ModificadaAlta (7.4)—

VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is used to download vCenter updates.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-3994",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "vCenter Server",
          "versions": [
            {
              "status": "affected",
              "version": "vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-10-20T17:15:12.967",
  "references": [
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2020-0023.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2020-0023.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is used to download vCenter updates."
    },
    {
      "lang": "es",
      "value": "VMware vCenter Server (versiones 6.7 anteriores a 6.7u3, versiones 6.6 anteriores a 6.5u3k), contiene una vulnerabilidad de secuestro de sesión en la función de actualización de la vCenter Server Appliance Management Interface debido a la falta de comprobación del certificado. Un actor malicioso con posicionamiento de red entre vCenter Server y un repositorio de actualizaciones puede ser capaz de realizar un secuestro de sesión cuando la vCenter Server Appliance Management Interface es usado para descargar actualizaciones de vCenter"
    }
  ],
  "lastModified": "2026-06-17T03:19:23.880",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "102115DE-F589-4153-9597-160D82FBAFC7",
              "versionEndExcluding": "3.9",
              "versionStartIncluding": "3.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23CFE5A5-A166-4FD5-BE97-5F16DAB1EAE0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF7DDB0C-3C07-4B5E-8B8A-0542FEE72877"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DD16169-A7DF-4604-888C-156A60018E32"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46FC9F34-C8FA-4AFE-9F4A-7CF9516BD4D9"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D26534EB-327B-4ED6-A3E1-005552CB1F9D"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:e:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "786CDD50-7E18-4437-8DB9-2D0ADECD436E"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:f:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2CE8DAE-0E78-4004-983D-1ECD8855EC33"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E51F433-1152-4E94-AF77-970230B1A574"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0064D104-E0D8-481A-9029-D3726A1A9CF4"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B4D3F61-6CD9-411F-A205-EB06A57EBB4E"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F72A1E9C-F960-4E8C-A46C-B38209E6349E"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C33CE46-F529-4EA9-9344-6ED3BFA7019D"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F1D8161-0E02-45C9-BF61-14799AB65E03"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F2CB1FF-6118-4875-945D-07BAA3A21FFA"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AEDA28A-5C8E-4E95-A377-3BE530DBEAB5"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDDC6510-3116-4578-80C8-8EF044A8370A"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8678DB48-CB98-4E4C-ADE6-CABA73265FEC"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBD9A341-1FBF-4E04-848B-550DEB27261A"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4955663C-1BB6-4F3E-9D4B-362DF144B7F1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE0F8453-3D6C-4F1C-9167-3F02E3D905DC"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E456F84C-A86E-4EA9-9A3E-BEEA662136E6"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5241C282-A02B-44B2-B6CA-BA3A99F9737C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04A60AC7-C2EA-4DBF-9743-54D708584AFA"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A91B0C4-F184-459E-AFD3-DE0E351CC964"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23253631-2655-48A8-9B00-CB984232329C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50C2A9A8-0E66-4702-BCD4-74622108E7A6"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE4D3E2A-C32D-408F-B811-EF8BC86F0D34"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31CA7802-D78D-4BAD-A45A-68B601C010C6"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B98981B-4721-4752-BAB4-361DB5AEB86F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}