Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2020-4006

VMware | Multiple ProductsAdded 2021-11-03Remediation Deadline 2022-05-03

Multiple VMware Products Command Injection Vulnerability

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-78

References