3. Broken authentication vulnerability (CVE-2020-3977)
Horizon DaaS contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.3.
CPE | Name | Operator | Version |
---|---|---|---|
horizon daas | lt | 8.0.1 Update 1 |
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3977
docs.vmware.com/en/VMware-Horizon-DaaS/services/rn/Horizon-DaaS-801-Release-Notes.html#rollup
my.vmware.com/web/vmware/downloads/details?downloadGroup=HORIZON_DAAS_801&productId=743&rPId=36148
www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L