CVE-2020-3952 is a critical authentication bypass vulnerability in the vmdir component of VMware vCenter Server, affecting both embedded and external Platform Services Controllers. With a CVSS score of 9.8, this flaw allows unauthenticated attackers to gain full control over affected systems due to improper access controls. It is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.7CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.