CVE-2020-3993: Medium severity vmware vcenter server and cloud foundation vulnerability
VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-3993?
CVE-2020-3993 is a security vulnerability in VMware NSX-T that allows a malicious actor with MITM positioning to compromise the transport node.
How does CVE-2020-3993 affect VMware NSX-T?
CVE-2020-3993 affects VMware NSX-T by allowing a KVM host to download and install packages from NSX manager, which can be exploited by an attacker with MITM positioning.
What is the severity of CVE-2020-3993?
CVE-2020-3993 has a severity rating of medium (5.9).
Which versions of VMware NSX-T are affected by CVE-2020-3993?
VMware NSX-T versions 3.x before 3.0.2 and 2.5.x before 2.5.2.2.0 are affected by CVE-2020-3993.
Where can I find more information about CVE-2020-3993?
You can find more information about CVE-2020-3993 on the VMware security advisories page: https://www.vmware.com/security/advisories/VMSA-2020-0023.html