CVE-2020-3945
published 2020-02-19CVE-2020-3945: vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.39%
69.2th percentile
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may obtain sensitive information
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vrealize_operations | >= 6.6.0 < 6.6.1 | 6.6.1 |
| vmware | vrealize_operations | >= 6.7.0 < 6.7.1 | 6.7.1 |
| vmware | vrealize_operations_for_horizon_adapter | — | — |
| vmware | vrealize_operations_for_horizon_adapter | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hmjr-69rr-r925: vRealize Operations for Horizon Adapter (6
ghsa_unreviewed·2022-05-24
CVE-2020-3945 [MEDIUM] CWE-200 GHSA-hmjr-69rr-r925: vRealize Operations for Horizon Adapter (6
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may obtain sensitive information
VMware
vRealize Operations for Horizon Adapter updates address multiple security vulnerabilities (CVE-2020-3943, CVE-2020-3944, CVE-2020-3945)
vendor_vmware·2020-02-18·CVSS 9.8
CVE-2020-3943 [CRITICAL] vRealize Operations for Horizon Adapter updates address multiple security vulnerabilities (CVE-2020-3943, CVE-2020-3944, CVE-2020-3945)
VMSA-2020-0003: vRealize Operations for Horizon Adapter updates address multiple security vulnerabilities (CVE-2020-3943, CVE-2020-3944, CVE-2020-3945)
vRealize Operations for Horizon Adapter uses a JMX RMI service which is not securely configured. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.0.
CVEs: CVE-2020-3943, CVE-2020-3944, CVE-2020-3945
Affected products: VMware Aria
Red Hat
chromium-browser: use-after-free in speech recognizer
vendor_redhat·2020-01-16·CVSS 8.8
CVE-2020-6378 [HIGH] CWE-416 chromium-browser: use-after-free in speech recognizer
chromium-browser: use-after-free in speech recognizer
Use after free in speech in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: use-after-free in speech recognizer
vendor_redhat·2020-01-16·CVSS 8.8
CVE-2020-6379 [HIGH] CWE-416 chromium-browser: use-after-free in speech recognizer
chromium-browser: use-after-free in speech recognizer
Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: extension message verification error
vendor_redhat·2020-01-16·CVSS 8.8
CVE-2020-6380 [HIGH] CWE-20 chromium-browser: extension message verification error
chromium-browser: extension message verification error
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted Chrome Extension.
Red Hat
chromium-browser: Use after free in audio
vendor_redhat·2020-01-07·CVSS 8.8
CVE-2020-6377 [HIGH] CWE-416 chromium-browser: Use after free in audio
chromium-browser: Use after free in audio
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-19
Published