CVE-2020-4006: Multiple VMware Products Command Injection Vulnerability
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Other sources
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4006?
CVE-2020-4006 is a command injection vulnerability in multiple VMware products, including Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector.
How severe is CVE-2020-4006?
CVE-2020-4006 has a severity score of 9.1, making it a critical vulnerability.
Which software is affected by CVE-2020-4006?
CVE-2020-4006 affects VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector.
How can an attacker exploit CVE-2020-4006?
An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands.
Is there a fix for CVE-2020-4006?
Yes, VMware has released patches to address CVE-2020-4006. It is recommended to update to the latest version of the affected software.