id: CVE-2020-3952 info: name: VMware vCenter Server LDAP Broken Access Control author: 0x_Akoko severity: critical description: | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. impact: | Unauthorized users may access sensitive functions, potentially leading to privilege escalation or data exposure. remediation: | Apply the latest security patches and updates provided by VMware to address access control issues. reference: - https://nvd.nist.gov/vuln/detail/CVE-2020-3952 - https://www.vmware.com/security/advisories/VMSA-2020-0006.html - https://github.com/guardicore/vmware_vcenter_cve_2020_3952 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2020-3952 cwe-id: CWE-306 epss-score: 0.90384 epss-percentile: 0.99787 cpe: cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:* metadata: verified: false max-request: 1 vendor: vmware product: vcenter_server tags: cve,cve2020,vmware,vcenter,ldap,auth-bypass,passive,kev,vkev http: - raw: - | POST /sdk/ HTTP/1.1 Host: {{Hostname}} Content-Type: text/xml SOAPAction: "urn:vim25/6.5" 00000001-00000001 <_this xsi:type="ManagedObjectReference" type="ServiceInstance">ServiceInstance matchers-condition: and matchers: - type: word part: body words: - 'RetrieveServiceContentResponse' - 'urn:vim' condition: or - type: word part: content_type words: - "text/xml" - type: status status: - 200 - type: dsl dsl: - compare_versions(version, '< 6.7.0') extractors: - type: regex part: body name: version group: 1 regex: - "([^<]+)" # digest: 4a0a00473045022100e7b13ed5e8986b5aa9d6cf57a2b2ebf2421493909da20113c1d00bcb534eeb2702202a13206e8b99db12cc8814c7cf7a9a027fa38b90a903125364cb590f4f450fc8:922c64590222798bb761d5b6d8e72950