EXPOSURES › CVE-2020-4006
CVE-2020-4006
HIGH ⌖ ON CISA KEV · EXPLOITEDCommand injection flaw in VMware Workspace One products allowed attackers with admin access to execute unrestricted OS commands.
An attacker needing only network access to port 8443 and a valid admin password could run arbitrary commands on the underlying OS, enabling full system compromise. DIBs must ensure all VMware Workspace One components are patched and that admin credentials are strictly controlled to prevent this class of exploit.
Shame score — A command injection flaw in widely deployed identity management products that required only valid admin credentials to execute unrestricted OS commands represents a severe, avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
"VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system."
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |