Skip to content
COOEY

EXPOSURES › CVE-2020-3952

CVE-2020-3952

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-3952 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrce

An unpatched directory traversal flaw in VMware vCenter's Syslog server allowed unauthenticated attackers to gain persistent remote access via reverse SSH backdoors.

The directory traversal vulnerability in VMware vCenter's Syslog server (CVE-2026-59310) was actively exploited in the wild to establish persistent remote access. DIB organizations must ensure vCenter is patched and network-segmented, as unauthenticated attackers can use this flaw as an initial access vector. This represents a severe, avoidable failure where a known vulnerability was left unpatched and exploited for long-term compromise.

Shame score — A maximum-severity directory traversal flaw was left unpatched and actively exploited in the wild to establish persistent remote access, demonstrating severe negligence and avoidability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
NIST and CISA treat CVE-2020-3952 as a high-severity, known exploited vulnerability, indicating severe fallout for VMware's security posture despite no direct press condemnation in the provided source
sploitus.com ↗ severe-fallout -0.80
Sploitus highlights the exploit's ability to taint the Administrators group, indicating severe fallout for VMware's access control failures.
"LDAP injection in VMware vCenter allows tainting the Administrators group via description attribute."
CISA ↗ severe-fallout -0.60
CISA's inclusion of the vulnerability in the KEV catalog indicates severe fallout and government-level concern for VMware's security posture.
"CISA Adds Three Known Exploited Vulnerabilities to Catalog"
cooey ↗ severe-fallout -0.60
NIST classifies the vulnerability as high severity with significant confidentiality, integrity, and availability impacts, reflecting severe fallout for VMware's security implementation.
"CVSS 9.8 for CVE-2020-3952... Confidentiality: HIGH Integrity: HIGH Availability: HIGH"
NIST ↗ severe-fallout +0.00
NIST's official site provides neutral institutional context without specific sentiment toward VMware.
xposedornot.com ↗ severe-fallout +0.00
XposedOrNot provides neutral breach directory context without specific sentiment toward VMware.
www.wibu.com ↗ severe-fallout +0.00
Wibu provides neutral security advisory context without specific sentiment toward VMware.
www.cvefind.com ↗ severe-fallout +0.00
CVE Find provides neutral database context without specific sentiment toward VMware.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized