EXPOSURES › CVE-2020-3952
CVE-2020-3952
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unpatched directory traversal flaw in VMware vCenter's Syslog server allowed unauthenticated attackers to gain persistent remote access via reverse SSH backdoors.
The directory traversal vulnerability in VMware vCenter's Syslog server (CVE-2026-59310) was actively exploited in the wild to establish persistent remote access. DIB organizations must ensure vCenter is patched and network-segmented, as unauthenticated attackers can use this flaw as an initial access vector. This represents a severe, avoidable failure where a known vulnerability was left unpatched and exploited for long-term compromise.
Shame score — A maximum-severity directory traversal flaw was left unpatched and actively exploited in the wild to establish persistent remote access, demonstrating severe negligence and avoidability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
"LDAP injection in VMware vCenter allows tainting the Administrators group via description attribute."
"CISA Adds Three Known Exploited Vulnerabilities to Catalog"
"CVSS 9.8 for CVE-2020-3952... Confidentiality: HIGH Integrity: HIGH Availability: HIGH"
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |