Vulnerabilities > Vmware

DATE CVE VULNERABILITY TITLE RISK
2020-11-24 CVE-2020-4001 Insecure Default Initialization of Resource vulnerability in VMWare Sd-Wan Orchestrator
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack.
network
low complexity
vmware CWE-1188
critical
9.8
2020-11-24 CVE-2020-4000 Path Traversal vulnerability in VMWare Sd-Wan Orchestrator
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal.
network
low complexity
vmware CWE-22
8.8
2020-11-24 CVE-2020-3985 Unspecified vulnerability in VMWare Sd-Wan Orchestrator 3.3.2/3.4.0/3.4.4
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privilege escalation issue.
network
low complexity
vmware
8.8
2020-11-24 CVE-2020-3984 SQL Injection vulnerability in VMWare Sd-Wan Orchestrator 3.3.2/3.4.0/3.4.4
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection.
network
low complexity
vmware CWE-89
6.5
2020-11-23 CVE-2020-4006 OS Command Injection vulnerability in VMWare products
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
network
low complexity
vmware CWE-78
critical
9.1
2020-11-20 CVE-2020-4005 Unspecified vulnerability in VMWare Cloud Foundation and Esxi
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls are being managed.
local
low complexity
vmware
7.8
2020-11-20 CVE-2020-4004 Use After Free vulnerability in VMWare products
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller.
local
low complexity
vmware CWE-416
8.2
2020-11-11 CVE-2020-5426 Cleartext Transmission of Sensitive Information vulnerability in VMWare Pivotal Scheduler
Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection.
network
low complexity
vmware CWE-319
critical
9.8
2020-10-31 CVE-2020-5425 Improper Authentication vulnerability in VMWare Single Sign-On for Tanzu 1.12.0/1.13.0
Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same username, from two different identity providers, one can acquire the token of the other and thus operate with their permissions.
network
high complexity
vmware CWE-287
7.9
2020-10-23 CVE-2020-3998 Unspecified vulnerability in VMWare Horizon Client
VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability.
network
low complexity
vmware
6.5