CVE-2020-3993
published 2020-10-20CVE-2020-3993: VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.93%
57.1th percentile
VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| broadcom | vmware_nsx-t_data_center | — | — |
| broadcom | vmware_nsx-t_data_center | >= 2.5.0 < 2.5.2.2.0 | 2.5.2.2.0 |
| broadcom | vmware_nsx-t_data_center | >= 3.0.0 < 3.0.2 | 3.0.2 |
| vmware | cloud_foundation | >= 3.0 < 3.10.1.1 | 3.10.1.1 |
| vmware | cloud_foundation | >= 4.0 < 4.1 | 4.1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rgcq-mpqc-xvh6: VMware NSX-T (3
ghsa_unreviewed·2022-05-24
CVE-2020-3993 [MEDIUM] GHSA-rgcq-mpqc-xvh6: VMware NSX-T (3
VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node.
VMware
VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
vendor_vmware·2020-10-20·CVSS 5.8
CVE-2020-3981 [MEDIUM] VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
VMSA-2020-0023: VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
OpenSLP as used in ESXi has a use-after-free issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995
Affected products: Fusion Pro, NSX-T, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware NSX, VMware Workstation, VMware vCenter Server, VMware vSphere, Workstation Player, Workstation Pro
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-20
Published