cve-2020-3952
CRITICAL CVSS 9.8 cisa_known_exploited
Description
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
Timeline
- Published
- 2021-11-03
- Last Modified
- 2021-11-03
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 9.8,
"datePublished": "2021-11-03",
"dateUpdated": "2021-11-03",
"description": "VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.",
"dueDate": "2022-05-03",
"id": "CVE-2020-3952",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-3952",
"product": "vCenter Server",
"requiredAction": "Apply updates per vendor instructions.",
"severity": "CRITICAL",
"source": "cisa_known_exploited",
"title": "VMware vCenter Server Information Disclosure Vulnerability",
"vendor": "VMware"
}
Enrichment data
Aggregated bundle (all enrichments)