CVE-2020-3956
CVE-2020-3956
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.
Productos afectados
n/a · VMware Cloud DirectorPoCs públicas encontradas — 3
githubgithub.com/aaronsvk/CVE-2020-3956★ 89cve_referencepacketstormsecurity.com/files/157909/vCloud-Director-9.7.0.15498291-Remote-Code-Execution.htmlno verificadoexploitdbwww.exploit-db.com/exploits/48540no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/157909/vCloud-Director-9.7.0.15498291-Remote-Code-Execution.htmlhttps://citadelo.com/en/blog/full-infrastructure-takeover-of-vmware-cloud-director-CVE-2020-3956/https://github.com/aaronsvk/CVE-2020-3956https://www.vmware.com/security/advisories/VMSA-2020-0010.html