« Volver al listado

CVE-2020-3985

Estado: ModificadaAlta (8.8)—

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privilege escalation issue. An authenticated SD-WAN Orchestrator user may exploit an application weakness and call a vulnerable API to elevate their privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-3985",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "VMware SD-WAN Orchestrator",
          "versions": [
            {
              "status": "affected",
              "version": "VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4."
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-11-24T16:15:16.370",
  "references": [
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2020-0025.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2020-0025.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privilege escalation issue. An authenticated SD-WAN Orchestrator user may exploit an application weakness and call a vulnerable API to elevate their privileges."
    },
    {
      "lang": "es",
      "value": "SD-WAN Orchestrator versiones 3.3.2 anteriores a 3.3.2 P3 y versiones 3.4.x anteriores a 3.4.4, permite un acceso para ajustar unos niveles de autorización arbitrarios que conllevan a un problema de escalada de privilegios. Un usuario autenticado de SD-WAN Orchestrator puede explotar la debilidad de una aplicación y llamar a una API vulnerable para escalar sus privilegios"
    }
  ],
  "lastModified": "2026-06-17T03:19:22.887",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:sd-wan_orchestrator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B81548A-23E9-47A8-99C4-B6FC77319F35",
              "versionEndExcluding": "3.4.4",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:sd-wan_orchestrator:3.3.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43CF669E-F5DF-46B4-934C-B705AB70511C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:sd-wan_orchestrator:3.3.2:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35653E6E-08FA-4431-B57D-D7F8CF55A0DA"
            },
            {
              "criteria": "cpe:2.3:a:vmware:sd-wan_orchestrator:3.3.2:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2038D63C-00D4-44A1-8B7D-1A54DD27C773"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}