CVE-2020-4006
published 2020-11-23CVE-2020-4006: VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
PriorityP186critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
23.77%
97.6th percentile
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | identity_manager_connector | — | — |
| vmware | identity_manager_connector | — | — |
| vmware | identity_manager_connector | — | — |
| vmware | one_access | — | — |
| vmware | one_access | — | — |
| vmware | vrealize_suite_lifecycle_manager | 8.0 – 8.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SIDs 57182 - 57185
- →Monitor for web shell installation on VMware Workspace ONE Access / Identity Manager systems following exploitation of the administrative configurator on port 8443. ↗
- →Enable SSL decryption in Cisco Secure Firewall and Snort to detect exploitation of CVE-2020-4006, as the vulnerability exploits applications leveraging SSL. ↗
- →Alert on unauthorized SAML token creation and presentation to services trusting SAML tokens, particularly following access to the VMware administrative configurator. ↗
- →The vulnerability requires network access to the administrative configurator on port 8443 (though this can be configured to be any port) — monitor for unexpected inbound connections to this service. ↗
- ·The administrative configurator port defaults to 8443 but can be reconfigured to any port, so detection rules should not be hardcoded to port 8443 alone. ↗
- ·Exploitation requires valid administrator credentials for the configurator admin account in addition to network access — brute-force or credential-stuffing detections on this interface are also relevant. ↗
- ·The workaround (removing the cfg webapp) applies ONLY to VMware Workspace ONE Access, VMware Identity Manager, and VMware Identity Manager Connector — do not apply to other VMware products. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck9.1CRITICAL
cisa9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hj5r-2q87-qf8g: VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability
ghsa_unreviewed·2022-05-24
CVE-2020-4006 [HIGH] CWE-77 GHSA-hj5r-2q87-qf8g: VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
VulnCheck
Multiple VMware Products Command Injection Vulnerability
vulncheck·2020·CVSS 9.1
CVE-2020-4006 [CRITICAL] CWE-78 Multiple VMware Products Command Injection Vulnerability
Multiple VMware Products Command Injection Vulnerability
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
Affected: VMware Multiple Products
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://arstechnica.com/information-technology/2020/12/nsa-says-russian-state-hackers-are-using-a-vmware-flaw-to-ransack-networks/; https://media.defense.gov/2021/A
CISA
Multiple VMware Products Command Injection Vulnerability
cisa·2021-11-03·CVSS 9.1
CVE-2020-4006 [CRITICAL] CWE-78 Multiple VMware Products Command Injection Vulnerability
Vulnerability: Multiple VMware Products Command Injection Vulnerability
Affected: VMware Multiple Products
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-4006
Remediation Due Date: 2022-05-03
VMware
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address command injection vulnerability
vendor_vmware·2020-11-23·CVSS 9.1
CVE-2020-4006 [CRITICAL] VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address command injection vulnerability
VMSA-2020-0027: VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address command injection vulnerability
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a Command Injection Vulnerability in the administrative configurator. VMware has evaluated this issue to be of 'Important' severity with a maximum CVSSv3 base score of 7.2.
CVEs: CVE-2020-4006
Affected products: VMware Aria, VMware Cloud Foundation, VMware Identity Manager, VMware Workspace ONE
No detection rules found.
No public exploits indexed.
Tenable
VMware Patches Multiple Vulnerabilities in Workspace ONE, Identity and Lifecycle Manager and vRealize (VMSA-2022-0011)
blogs_tenable·2022-04-07
VMware Patches Multiple Vulnerabilities in Workspace ONE, Identity and Lifecycle Manager and vRealize (VMSA-2022-0011)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Russia-Ukraine Crisis: How to Strengthen Your Security Posture to Protect against Cyber Attack, based on CISA Guidelines
blogs_qualys·2022-02-26
Russia-Ukraine Crisis: How to Strengthen Your Security Posture to Protect against Cyber Attack, based on CISA Guidelines
## Table of Contents
Protecting Customer Data on Qualys Cloud Platform
Urgent: Assess and Heighten Your Security Posture
Step 1: Monitor Your Shodan/Internet Exposed Assets
Step 2: Detect, Prioritize and Remediate CISAs Catalog ofKnown Exploited Vulnerabilities
Step 3: Protect Your Cloud Services and Office 365
Step 4: Continuously Detect any Potential Threats and Attacks
Take Action to Learn More about How to Strengthen Your Defenses
CISA has created Shields Up as a response to the Russian invasion of Ukraine. Qualys is responding with additional security, monitoring and governance measures. This blog details how and what our enterprise customers can do to immediately strengthen their security posture and meet CISA’s recommendations.
With the invasion of Ukraine by Russia, the U.
Tenable
Government Advisories Warn of APT Activity Resulting from Russian Invasion of Ukraine
blogs_tenable·2022-02-24
Government Advisories Warn of APT Activity Resulting from Russian Invasion of Ukraine
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
blogs_unit42·2022-02-22
Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
Threat Research Center
Threat Research
Malware
## Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
Unit 42
Published: February 22, 2022
Malware
Threat Research
DDoS
Defacement
Gamaredon
HermeticWiper
Nation-state
Russia
Trident Ursa
Ukraine
WhisperGate
## Executive Summary
Over the past several weeks, Russia-Ukraine cyber activity has escalated substantially. Beginning on Feb. 15, a series of distributed denial of service (DDoS) attacks commenced. These attacks have continued over the past week, impacting both the Ukrainian government and banking institutions. On Feb. 23, a new variant of wiper malware named HermeticWiper was discovered in Ukraine. Shortl
Unit42
Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
blogs_unit42·2022-02-22
Russia-Ukraine Cyberattacks (Updated): How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon, Website Defacement, Phishing and Scams
## Executive Summary
Over the past several weeks, Russia-Ukraine cyber activity has escalated substantially. Beginning on Feb. 15, a series of distributed denial of service (DDoS) attacks commenced. These attacks have continued over the past week, impacting both the Ukrainian government and banking institutions. On Feb. 23, a new variant of wiper malware named HermeticWiper was discovered in Ukraine. Shortly after, a new round of website defacement attacks were also observed impacting Ukrainian government organizations.
Consistent with our previous reporting on the topic, several western governments have issued recommendations for their populations to prepare for cyberattacks that could disrupt, disable or destroy critical infrastructure. We have already observed an increase in Russian c
Krebs
Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020?
blogs_krebs·2021-04-16
Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020?
On Aug. 13, 2020, someone uploaded a suspected malicious file to VirusTotal, a service that scans submitted files against more than five dozen antivirus and security products. Last month, Microsoft and FireEye identified that file as a newly-discovered fourth malware backdoor used in the sprawling SolarWinds supply chain hack. An analysis of the malicious file and other submissions by the same VirusTotal user suggest the account that initially flagged the backdoor as suspicious belongs to IT personnel at the National Telecommunications and Information Administration (NTIA), a division of the U.S. Commerce Department that handles telecommunications and Internet policy.
Both Microsoft and FireEye published blog posts on Mar. 4 concerning a new backdoor found on high-value targets that were
Krebs
Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020?
blogs_krebs·2021-04-16
Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020?
On Aug. 13, 2020, someone uploaded a suspected malicious file to VirusTotal , a service that scans submitted files against more than five dozen antivirus and security products. Last month, Microsoft and FireEye identified that file as a newly-discovered fourth malware backdoor used in the sprawling SolarWinds supply chain hack . An analysis of the malicious file and other submissions by the same VirusTotal user suggest the account that initially flagged the backdoor as suspicious belongs to IT personnel at the National Telecommunications and Information Administration (NTIA), a division of the U.S. Commerce Department that handles telecommunications and Internet policy.
Both Microsoft and FireEye published blog posts on Mar. 4 concerning a new backdoor found on high-value targets that wer
Talos
Threat Advisory: NSA SVR Advisory Coverage
blogs_talos·2021-04-15·CVSS 9.1
[CRITICAL] Threat Advisory: NSA SVR Advisory Coverage
## Threat Advisory: NSA SVR Advisory Coverage
The U.S. National Security Agency released an advisory outlining several vulnerabilities that the Russian Foreign Intelligence Services (SVR) is exploiting in the wild. The U.S. formally attributed the recent SolarWinds supply chain attack to the SVR group in this advisory and detailed more of the group's tactics, techniques and procedures.
The exploits included a series of five CVEs that affect VPN solutions, collaboration suite software and virtualization technologies. All five of the CVEs have been patched — Cisco Talos encourages everyone with the affected software update immediately. Some of these vulnerabilities also have working metasploit modules and are currently being widely exploited. Please note that some of these vulnerabilities
Talos
Threat Advisory: NSA SVR Advisory Coverage
blogs_talos·2021-04-15·CVSS 9.1
[CRITICAL] Threat Advisory: NSA SVR Advisory Coverage
The U.S. National Security Agency released an advisory outlining several vulnerabilities that the Russian Foreign Intelligence Services (SVR) is exploiting in the wild. The U.S. formally attributed the recent SolarWinds supply chain attack to the SVR group in this advisory and detailed more of the group's tactics, techniques and procedures.
The exploits included a series of five CVEs that affect VPN solutions, collaboration suite software and virtualization technologies. All five of the CVEs have been patched — Cisco Talos encourages everyone with the affected software update immediately. Some of these vulnerabilities also have working metasploit modules and are currently being widely exploited. Please note that some of these vulnerabilities exploit applications leveraging SSL. This means
Unit42
SolarStorm Supply Chain Attack Timeline
blogs_unit42·2020-12-23
SolarStorm Supply Chain Attack Timeline
## Executive Summary
On Dec. 13, the cyber community became aware of one of the most significant cybersecurity events of our time, impacting both commercial and government organizations around the world. The event was a supply chain attack on SolarWinds OrionⓇ software conducted by suspected nation-state operators that we are tracking as SolarStorm. Unit 42 was able to connect this event back to an attack we successfully prevented earlier this year. On Dec. 18, we launched a SolarStorm Rapid Assessment program resulting in more than 600 companies requesting this service within the first four days.
While this is not the first software supply chain compromise, it may be the most notable, as the attacker was trying to gain widespread, persistent access to a number of critical networks. Give
Unit42
SolarStorm Supply Chain Attack Timeline
blogs_unit42·2020-12-23
SolarStorm Supply Chain Attack Timeline
Threat Research Center
High Profile Threats
Vulnerabilities
## SolarStorm Supply Chain Attack Timeline
Unit 42
Published: December 23, 2020
High Profile Threats
Malware
Vulnerabilities
Software supply-chain attack
SolarStorm
SolarWinds
SUPERNOVA
Supply-chain attack
## Executive Summary
On Dec. 13, the cyber community became aware of one of the most significant cybersecurity events of our time, impacting both commercial and government organizations around the world. The event was a supply chain attack on SolarWinds Orion Ⓡ software conducted by suspected nation-state operators that we are tracking as SolarStorm. Unit 42 was able to connect this event back to an attack we successfully prevented earlier this year. On Dec. 18, we launched a SolarStorm Rapid Assessment progra
Krebs
VMware Flaw a Vector in SolarWinds Breach?
blogs_krebs·2020-12-19·CVSS 9.1
[CRITICAL] VMware Flaw a Vector in SolarWinds Breach?
U.S. government cybersecurity agencies warned this week that the attackers behind the widespread hacking spree stemming from the compromise at network software firm SolarWinds used weaknesses in other, non-SolarWinds products to attack high-value targets. According to sources, among those was a flaw in software virtualization platform VMware, which the U.S. National Security Agency (NSA) warned on Dec. 7 was being used by Russian hackers to impersonate authorized users on victim networks.
On Dec. 7, 2020, the NSA said “Russian state-sponsored malicious cyber actors are exploiting a vulnerability in VMware Access and VMware Identity Manager products, allowing the actors access to protected data and abusing federated authentication.”
VMware released a software update to plug the security h
Krebs
VMware Flaw a Vector in SolarWinds Breach?
blogs_krebs·2020-12-18·CVSS 9.1
[CRITICAL] VMware Flaw a Vector in SolarWinds Breach?
U.S. government cybersecurity agencies warned this week that the attackers behind the widespread hacking spree stemming from the compromise at network software firm SolarWinds used weaknesses in other, non-SolarWinds products to attack high-value targets. According to sources, among those was a flaw in software virtualization platform VMware , which the U.S. National Security Agency (NSA) warned on Dec. 7 was being used by Russian hackers to impersonate authorized users on victim networks.
On Dec. 7, 2020, the NSA said “Russian state-sponsored malicious cyber actors are exploiting a vulnerability in VMware Access and VMware Identity Manager products, allowing the actors access to protected data and abusing federated authentication.”
VMware released a software update to plug the security
Unit42
Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006)
blogs_unit42·2020-12-10·CVSS 9.1
CVE-2020-4006 [CRITICAL] Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006)
## Executive Summary
On Dec. 7, 2020, the National Security Agency (NSA) published a cybersecurity advisory indicating they observed Russian state-sponsored actors exploiting a VMware command injection vulnerability (CVE-2020-4006). VMware issued a patch for the vulnerability on Dec. 3, 2020. The vulnerability affects the following VMware products:
- VMware Access®3 20.01 and 20.10 on Linux®4
- VMware vIDM®5 3.3.1, 3.3.2 and 3.3.3 on Linux
- VMware vIDM Connector 3.3.1, 3.3.2, 3.3.3, 19.03
- VMware Cloud Foundation®6 4.x
- VMware vRealize Suite Lifecycle Manager®7 8.x
The vulnerability requires network access to the administrative configurator on port 8443 (though this can be configured to be any port) and a valid password for the configurator admin account. If these conditions exist, a
Unit42
Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006)
blogs_unit42·2020-12-10·CVSS 9.1
CVE-2020-4006 [CRITICAL] Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006)
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006)
Shawn Westfall
Published: December 9, 2020
High Profile Threats
Vulnerabilities
CVE-2020-4006
VMware
## Executive Summary
On Dec. 7, 2020, the National Security Agency (NSA) published a cybersecurity advisory indicating they observed Russian state-sponsored actors exploiting a VMware command injection vulnerability (CVE-2020-4006). VMware issued a patch for the vulnerability on Dec. 3, 2020. The vulnerability affects the following VMware products:
VMware Access®3 20.01 and 20.10 on Linux®4
VMware vIDM®5 3.3.1, 3.3.2 and 3.3.3 on Linux
VMware vIDM Connector 3.3.1, 3.3.2, 3.3.3, 19.03
VMware Cloud Foundation®6 4.x
VMware vRealize Suite Lifecy
Tenable
CVE-2020-4006: VMware Command Injection Flaw Exploited by Russian State-Sponsored Threat Actors
blogs_tenable·2020-12-08·CVSS 9.1
[CRITICAL] CVE-2020-4006: VMware Command Injection Flaw Exploited by Russian State-Sponsored Threat Actors
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
7th December – Threat Intelligence Bulletin
blogs_checkpoint·2020-12-07
CVE-2020-8913 7th December – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 7th December – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 7th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point has published a warning against cyber attackers leveraging the online shopping spree around Thanksgiving to distribute shipping and package tracking-related phishing email campaigns. Some 440% increase in campaigns impersonating online shopping services was observed throughout November.
Cyber Attackers have
Checkpoint
30th November – Threat Intelligence Bulletin
blogs_checkpoint·2020-11-30
CVE-2020-28948 30th November – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th November – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 30th November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has analyzed a new global campaign that distributed Bandook, a 13-year old backdoor Trojan. Previous campaigns utilizing the malware were attributed to the Kazakh and the Lebanese governments. The current campaign targets multiple sectors and locations, hinting that the malware is part of an infra
2020-11-23
Published
2021-11-03
Added to CISA KEV
Exploited in the wild