CVE-2020-4006

CVE Published 2020-11-23
Related CWE(s) CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Related Vendor(s) vmware
Related Product(s) one_access, identity_manager_connector, identity_manager, vrealize_suite_lifecycle_manager, cloud_foundation
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.1 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References