Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-4008

13
FAUCET Score

CVE-2020-4008 describes an insecure file handling vulnerability in the installer for VMware Carbon Black Cloud macOS Sensor versions prior to 3.5.1, affecting macOS and Carbon Black Cloud products. This low-severity vulnerability (CVSS 3.6) requires local access and high attack complexity, allowing a malicious actor to overwrite a limited number of files during sensor installation, potentially leading to low integrity and availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.5.1CPE matchmatch criteria
cpe:2.3:a:vmware:carbon_black_cloud:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.6LOW

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.0
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 39th percentile among its peer group of 223 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (8)

esetvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
mariadbvendor investigatingvia llm_extracted
omronvendor investigatingvia llm_extracted
openrefinevendor investigatingvia llm_extracted
pnpmvendor investigatingvia llm_extracted
twiliovendor investigatingvia llm_extracted
vmwarevendor investigatingvia nvd_reference
View patch

Vendor Advisories (7)

twiliollm-twilio-001a35e75b19b2f5MEDIUM

Carbon Black Installer Multiple Vulnerabilities

Dec 15, 2020
esetllm-eset-14e6fa4d3198bc56MEDIUM

Carbon Black Installer Multiple Vulnerabilities

Dec 15, 2020
hyperledgerllm-hyperledger-59f94f1f5a29fedeMEDIUM

Carbon Black Installer Multiple Vulnerabilities

Dec 15, 2020
pnpmllm-pnpm-f44d29cbfc504689MEDIUM

Carbon Black Installer Multiple Vulnerabilities

Dec 15, 2020
omronllm-omron-63bf51b6b1192e1bMEDIUM

Carbon Black Installer Multiple Vulnerabilities

Dec 15, 2020
openrefinellm-openrefine-675908daf52b7d39MEDIUM

Carbon Black Installer Multiple Vulnerabilities

Dec 15, 2020
mariadbllm-mariadb-09943ebd879e3ea2MEDIUM

Carbon Black Installer Multiple Vulnerabilities

Dec 15, 2020

References

vmware.com / security/advisories/VMSA-2020-0028.html
Vendor Advisory