CVE-2020-3973 is a high-severity blind SQL injection vulnerability in VeloCloud Orchestrator, affecting both Linux and VMware deployments. An authenticated attacker with tenant access can exploit this flaw by submitting specially crafted SQL queries, bypassing input validation to gain unauthorized access to sensitive data. With a CVSS score of 8.8, the vulnerability presents a significant risk of high confidentiality, integrity, and availability impact. While no public exploits, Metasploit modules, or active exploitation have been identified, and community discussion is minimal, the potential for a sophisticated attacker to leverage this vulnerability remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.1, < 3.3.2CPE matchmatch criteria | cpe:2.3:a:vmware:velocloud_orchestrator:*:*:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:a:vmware:velocloud_orchestrator:3.3.2:-:*:*:*:*:*:* | ||
3.4.0CPE matchmatch criteria | cpe:2.3:a:vmware:velocloud_orchestrator:3.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.