Skip to content
COOEY

EXPOSURES › CVE-2020-4006

CVE-2020-4006

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-4006 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Command injection flaw in VMware Workspace One products allowed attackers with admin access to execute unrestricted OS commands.

An attacker needing only network access to port 8443 and a valid admin password could run arbitrary commands on the underlying OS, enabling full system compromise. DIBs must ensure all VMware Workspace One components are patched and that admin credentials are strictly controlled to prevent this class of exploit.

Shame score — A command injection flaw in widely deployed identity management products that required only valid admin credentials to execute unrestricted OS commands represents a severe, avoidable security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Command injection in core identity management products allows unrestricted OS command execution, representing a critical security failure with severe fallout for VMware's security posture.
cooey ↗ severe-fallout -0.60
Critical vulnerability in core identity management products allows unrestricted OS command execution, representing a severe security failure.
"VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized