vulnerability
VMware vCenter Server: updates address sensitive information disclosure vulnerability in the VMware Directory Service (VMSA-2020-0006) (CVE-2020-3952)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | Mar 25, 2020 | Mar 25, 2020 | Jan 20, 2026 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Mar 25, 2020
Added
Mar 25, 2020
Modified
Jan 20, 2026
Description
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
Solution
vmware-vcenter-server-upgrade-latest
References
- CVE-2020-3952
- https://attackerkb.com/topics/CVE-2020-3952
- URL-http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authentication-Bypass.html
- URL-https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23573
- URL-https://www.vmware.com/security/advisories/VMSA-2020-0006
- CWE-306
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.