CVE-2020-4006 is a critical command injection vulnerability affecting VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector products across Linux and Microsoft platforms. With a CVSS score of 9.1, this flaw allows an unauthenticated attacker to execute arbitrary commands with high privileges over the network, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and extensive media coverage linking it to significant cyberattacks like SolarWinds. Despite no public Metasploit or ExploitDB modules, the high number of community discussions indicates significant attention and potential for further exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.1CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.1:*:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.2:*:*:*:*:*:*:* | ||
3.3.3CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:* | ||
3.3.1CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager_connector:3.3.1:*:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager_connector:3.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.