← Back

CVE-2020-3956

nvd nist
Published: May 20, 2020Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.

Affected (4)

1 product
Vcloud Director
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Vmware
From 10.0.0.0 to 10.0.0.2
From 9.5.0.0 to 9.5.0.6
From 9.7.0.0 to 9.7.0.5
Running on/withPlatform Versions
Vmware
Photon Os
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 9.1.0.0 to 9.1.0.4
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (8)

Source: security@vmware.com
ExploitThird Party Advisory
Source: security@vmware.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.