{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-3952/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-3952/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-3952/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-3952/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-3952/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-3952"},"sightings":{"href":"/api/v1/sightings/cve-2020-3952"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.90384,"kev":true,"percentile":0.99794},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-3952.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-3952\n\ninfo:\n  name: VMware vCenter Server LDAP Broken Access Control\n  author: 0x_Akoko\n  severity: critical\n  description: |\n    Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.\n  impact: |\n    Unauthorized users may access sensitive functions, potentially leading to privilege escalation or data exposure.\n  remediation: |\n    Apply the latest security patches and updates provided by VMware to address access control issues.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-3952\n    - https://www.vmware.com/security/advisories/VMSA-2020-0006.html\n    - https://github.com/guardicore/vmware_vcenter_cve_2020_3952\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-3952\n    cwe-id: CWE-306\n    epss-score: 0.90384\n    epss-percentile: 0.99794\n    cpe: cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*\n  metadata:\n    verified: false\n    max-request: 1\n    vendor: vmware\n    product: vcenter_server\n  tags: cve,cve2020,vmware,vcenter,ldap,auth-bypass,passive,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /sdk/ HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: text/xml\n        SOAPAction: \"urn:vim25/6.5\"\n\n        <?xml version=\"1.0\" encoding=\"UTF-8\"?>\n        <soap:Envelope xmlns:soap=\"http://schemas.xmlsoap.org/soap/envelope/\" xmlns:xsd=\"http://www.w3.org/2001/XMLSchema\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\">\n           <soap:Header>\n              <operationID>00000001-00000001</operationID>\n           </soap:Header>\n           <soap:Body>\n              <RetrieveServiceContent xmlns=\"urn:internalvim25\">\n                 <_this xsi:type=\"ManagedObjectReference\" type=\"ServiceInstance\">ServiceInstance</_this>\n              </RetrieveServiceContent>\n           </soap:Body>\n        </soap:Envelope>\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - 'RetrieveServiceContentResponse'\n          - 'urn:vim'\n        condition: or\n\n      - type: word\n        part: content_type\n        words:\n          - \"text/xml\"\n\n      - type: status\n        status:\n          - 200\n\n      - type: dsl\n        dsl:\n          - compare_versions(version, '< 6.7.0')\n\n    extractors:\n      - type: regex\n        part: body\n        name: version\n        group: 1\n        regex:\n          - \"<version>([^<]+)</version>\"\n# digest: 4a0a00473045022100b86e66c4b27a326fc5a33426824994d0c0db24f6c90ba22404f6d2a808e8922c02204a347235cb79b4125b17b74f261010a3e50d3c07041692841d3a24b3df33052b:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-3952"}