Vmware Horizon Daas vulnerabilities
4 known vulnerabilities affecting vmware/horizon_daas.
Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-3977MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.0.1v7.0.02020-09-22
CVE-2020-3977 [MEDIUM] CWE-306 CVE-2020-3977: VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerabili
VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account o
nvd
CVE-2019-5544CRITICALCVSS 9.8KEVPoC≥ 8.0.0, < 9.0.0.02019-12-06
CVE-2019-5544 [CRITICAL] CWE-787 CVE-2019-5544: OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evalu
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
nvd
CVE-2018-6960HIGHCVSS 8.8≥ 7.0.0, < 8.0.0v7.x before 8.0.02018-04-20
CVE-2018-6960 [HIGH] CWE-287 CVE-2018-6960: VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow
VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.
cvelistv5nvd
CVE-2017-4897MEDIUMCVSS 5.5≤ 6.1.6vprior to 7.0.02017-05-31
CVE-2017-4897 [MEDIUM] CWE-20 CVE-2017-4897: VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation
VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim to download a specially crafted RDP
cvelistv5nvd