CVE-2020-3985 is a high-severity privilege escalation vulnerability affecting VMware SD-WAN Orchestrator versions 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4. An authenticated user can exploit an application weakness by calling a vulnerable API to set arbitrary authorization levels, thereby elevating their privileges. This network-exploitable vulnerability has a CVSS score of 8.8, indicating high impact on confidentiality, integrity, and availability, with low attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.4.0, < 3.4.4CPE matchmatch criteria | cpe:2.3:a:vmware:sd-wan_orchestrator:*:*:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:a:vmware:sd-wan_orchestrator:3.3.2:-:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:a:vmware:sd-wan_orchestrator:3.3.2:p1:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:a:vmware:sd-wan_orchestrator:3.3.2:p2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.