CVE-2020-3956
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.
Affected (4)
Products: Vmware: Vcloud Director
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.0.0 to 10.0.0.2 |
| Running on/with | Platform Versions |
|---|---|
Vmware Photon Os | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.1.0.0 to 9.1.0.4 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
References (8)
Source: security@vmware.com
ExploitThird Party AdvisoryVDB Entry
Source: security@vmware.com
ExploitThird Party Advisory
Source: security@vmware.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.