Vulnerabilities > CVE-2020-4001 - Insecure Default Initialization of Resource vulnerability in VMWare Sd-Wan Orchestrator 3.3.2/3.4.0/4.0.0

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
vmware
CWE-1188
critical

Summary

The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.

Vulnerable Configurations

Part Description Count
Application
Vmware
5