CVE-2020-3952
9.8
CRITICAL
CVSS 3.1
EPSS 90.4% · 100th pctCISA KEV · Exploited in the wild
2020-04-10•Updated 2025-10-21•KEV 2021-11-03
CISA Known Exploited Vulnerabilities
VMware vCenter Server Information Disclosure Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Added to KEV
2021-11-03
Remediation due
2022-05-03
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2020-3952
Description
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
Severity
CVSS 3.1 · CISA9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal
Affected Products
| Vendor | Product | Affected versions |
|---|---|---|
| - | VMware vCenter Server | vCenter Server 6.7 (embedded or external PSC) prior to 6.7u3f is affected by CVE-2020-3952 if it was upgraded from a previous release line such as 6.0 or 6.5. Clean installations of vCenter Server 6.7 (embedded or external PSC) are not affected. |
References
2 LinksRecord Details
Published
2020-04-10
Last updated
2025-10-21
Assigner (CNA)
vmware
Credited to
-
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.