cbcvebase.
CVE-2020-4006
published 2020-11-23

CVE-2020-4006: VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

PriorityP186critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
23.77%
97.6th percentile
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Affected

11 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation
vmwarecloud_foundation
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager_connector
vmwareidentity_manager_connector
vmwareidentity_manager_connector
vmwareone_access
vmwareone_access
vmwarevrealize_suite_lifecycle_manager8.0 – 8.2

Detection & IOCsextracted from sources · hover to see the quote

port8443
path/opt/vmware/horizon/workspace/webapps/cfg
path/opt/vmware/horizon/workspace/webapps/hc
snort
SIDs 57182 - 57185
  • Monitor for web shell installation on VMware Workspace ONE Access / Identity Manager systems following exploitation of the administrative configurator on port 8443.
  • Enable SSL decryption in Cisco Secure Firewall and Snort to detect exploitation of CVE-2020-4006, as the vulnerability exploits applications leveraging SSL.
  • Alert on unauthorized SAML token creation and presentation to services trusting SAML tokens, particularly following access to the VMware administrative configurator.
  • The vulnerability requires network access to the administrative configurator on port 8443 (though this can be configured to be any port) — monitor for unexpected inbound connections to this service.
  • ·The administrative configurator port defaults to 8443 but can be reconfigured to any port, so detection rules should not be hardcoded to port 8443 alone.
  • ·Exploitation requires valid administrator credentials for the configurator admin account in addition to network access — brute-force or credential-stuffing detections on this interface are also relevant.
  • ·The workaround (removing the cfg webapp) applies ONLY to VMware Workspace ONE Access, VMware Identity Manager, and VMware Identity Manager Connector — do not apply to other VMware products.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck9.1CRITICAL
cisa9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.