Lucene search

K
cveVmwareCVE-2020-3943
HistoryFeb 19, 2020 - 9:15 p.m.

CVE-2020-3943

2020-02-1921:15:11
vmware
web.nvd.nist.gov
55
cve-2020-3943
vrealize operations
horizon adapter
remote code execution
nvd
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.009

Percentile

82.7%

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.

Affected configurations

Nvd
Node
microsoftwindowsMatch-
AND
vmwarevrealize_operationsRange6.6.06.6.1horizon
OR
vmwarevrealize_operationsRange6.7.06.7.1horizon
VendorProductVersionCPE
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
vmwarevrealize_operations*cpe:2.3:a:vmware:vrealize_operations:*:*:*:*:*:horizon:*:*

CNA Affected

[
  {
    "product": "vRealize Operations for Horizon Adapter",
    "vendor": "VMWare",
    "versions": [
      {
        "status": "affected",
        "version": "6.7.x prior to 6.7.1"
      },
      {
        "status": "affected",
        "version": "6.6.x prior to 6.6.1"
      }
    ]
  }
]

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.009

Percentile

82.7%

Related for CVE-2020-3943