id: CVE-2020-3952
info:
name: VMware vCenter Server LDAP Broken Access Control
author: 0x_Akoko
severity: critical
description: |
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
impact: |
Unauthorized users may access sensitive functions, potentially leading to privilege escalation or data exposure.
remediation: |
Apply the latest security patches and updates provided by VMware to address access control issues.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2020-3952
- https://www.vmware.com/security/advisories/VMSA-2020-0006.html
- https://github.com/guardicore/vmware_vcenter_cve_2020_3952
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2020-3952
cwe-id: CWE-306
epss-score: 0.90384
epss-percentile: 0.99787
cpe: cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*
metadata:
verified: false
max-request: 1
vendor: vmware
product: vcenter_server
tags: cve,cve2020,vmware,vcenter,ldap,auth-bypass,passive,kev,vkev
http:
- raw:
- |
POST /sdk/ HTTP/1.1
Host: {{Hostname}}
Content-Type: text/xml
SOAPAction: "urn:vim25/6.5"
00000001-00000001
<_this xsi:type="ManagedObjectReference" type="ServiceInstance">ServiceInstance
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'RetrieveServiceContentResponse'
- 'urn:vim'
condition: or
- type: word
part: content_type
words:
- "text/xml"
- type: status
status:
- 200
- type: dsl
dsl:
- compare_versions(version, '< 6.7.0')
extractors:
- type: regex
part: body
name: version
group: 1
regex:
- "([^<]+)"
# digest: 4a0a00473045022100e7b13ed5e8986b5aa9d6cf57a2b2ebf2421493909da20113c1d00bcb534eeb2702202a13206e8b99db12cc8814c7cf7a9a027fa38b90a903125364cb590f4f450fc8:922c64590222798bb761d5b6d8e72950