CVE-2020-4001: Critical severity vmware velocloud orchestrator vulnerability
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4001?
CVE-2020-4001 is classified as a critical vulnerability due to the risk of unauthorized access from default passwords.
How do I fix CVE-2020-4001?
To fix CVE-2020-4001, update the SD-WAN Orchestrator to the latest version and ensure that all default passwords are changed immediately.
Which versions of VMware SD-WAN Orchestrator are affected by CVE-2020-4001?
CVE-2020-4001 affects VMware SD-WAN Orchestrator versions 3.3.2, 3.4.x, and 4.0.x.
What type of attack can exploit CVE-2020-4001?
CVE-2020-4001 can be exploited through a Pass-the-Hash attack due to the presence of default passwords.
Is CVE-2020-4001 related to account security?
Yes, CVE-2020-4001 raises significant concerns regarding account security through the use of default credentials.