First published: Tue Oct 20 2020(Updated: )
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is used to download vCenter updates.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | >=3.0<3.9 | |
VMware vCenter Server | =6.5 | |
VMware vCenter Server | =6.5-a | |
VMware vCenter Server | =6.5-b | |
VMware vCenter Server | =6.5-c | |
VMware vCenter Server | =6.5-d | |
VMware vCenter Server | =6.5-e | |
VMware vCenter Server | =6.5-f | |
VMware vCenter Server | =6.5-update1 | |
VMware vCenter Server | =6.5-update1b | |
VMware vCenter Server | =6.5-update1c | |
VMware vCenter Server | =6.5-update1d | |
VMware vCenter Server | =6.5-update1e | |
VMware vCenter Server | =6.5-update1g | |
VMware vCenter Server | =6.5-update2 | |
VMware vCenter Server | =6.5-update2b | |
VMware vCenter Server | =6.5-update2c | |
VMware vCenter Server | =6.5-update2d | |
VMware vCenter Server | =6.5-update2g | |
VMware vCenter Server | =6.5-update3 | |
VMware vCenter Server | =6.5-update3d | |
VMware vCenter Server | =6.7 | |
VMware vCenter Server | =6.7-a | |
VMware vCenter Server | =6.7-b | |
VMware vCenter Server | =6.7-d | |
VMware vCenter Server | =6.7-update1 | |
VMware vCenter Server | =6.7-update1b | |
VMware vCenter Server | =6.7-update2 | |
VMware vCenter Server | =6.7-update2a | |
VMware vCenter Server | =6.7-update2c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3994 is a session hijack vulnerability in VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) due to a lack of certificate validation.
CVE-2020-3994 has a severity score of 7.4 and is considered high severity.
VMware vCenter Server versions 6.7 before 6.7u3 and 6.6 before 6.5u3k are affected by CVE-2020-3994.
The CWE ID for CVE-2020-3994 is 295.
Yes, a fix is available. Please refer to the VMware security advisory linked below for more information on how to apply the fix.