CVE-2018-6979 describes a SAML authentication bypass vulnerability in multiple versions of VMware Workspace ONE Unified Endpoint Management Console (A/W Console) that can be exploited during device enrollment. This high-severity vulnerability (CVSS 7.4) allows a remote attacker to impersonate an authorized SAML session, leading to high confidentiality and integrity impacts if certificate-based authentication is enabled. If not, it results in information disclosure. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.1.0.0, < 9.1.5.6CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_console:*:*:*:*:*:*:*:* | ||
>= 9.2.0.0, < 9.2.3.27CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_console:*:*:*:*:*:*:*:* | ||
>= 9.3.0.0, < 9.3.0.25CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_console:*:*:*:*:*:*:*:* | ||
>= 9.4.0.0, < 9.4.0.22CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_console:*:*:*:*:*:*:*:* | ||
>= 9.5.0.0, < 9.5.0.16CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_console:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.