CVE Database
/

CVE-2020-3994

Back to search

CVE-2020-3994

Published: Oct 20, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is used to download vCenter updates.

VendorProductVersions

n/a

vCenter Server

affected
vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now