CVE-2020-3994
Published: Oct 20, 2020
Modified: Aug 4, 2024
Description
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is used to download vCenter updates.
| Vendor | Product | Versions |
|---|---|---|
n/a | vCenter Server | affected vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now