CVE-2020-3992 is a critical use-after-free vulnerability in OpenSLP, affecting VMware ESXi and Cloud Foundation. This flaw allows unauthenticated attackers on the management network to achieve remote code execution by accessing port 427. With a CVSS score of 9.8 (CRITICAL), the vulnerability poses a severe risk due to its network-based attack vector, low complexity, and complete compromise potential (confidentiality, integrity, availability). It is actively exploited in the wild, notably by ransomware campaigns like ESXiArgs, and has garnered significant community discussion and media coverage, despite the absence of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 3.10.1.2CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
>= 4.0, < 4.1.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:2:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.