CVE-2020-4006 | VMwareºÅÁî×¢Èë·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-11-240x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-4006 | ʱ ¼ä | 2020-10-24 |
Àà ÐÍ | ºÅÁî×¢Èë | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò |
0x01 ·ì϶ÏêÇé

2020Äê11ÔÂ23ÈÕ£¬VMware°ä²¼°²È«²¼¸æ£¬Æä¶à¸ö²úÆ·ºÍ×é¼þµÄÖÎÀíÅäÖÃÆ÷ÖдæÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¨CVE-2020-4006£©£¬ÆäCVSSÆÀ·Ö9.1¡£
ÓµÓÐÖÎÀíÅäÖÃÆ÷8443¶Ë¿ÚµÄÍøÂç½Ó¼ûȨÏÞ²¢Õ¼ÓÐÖÎÀíÅäÖÃÆ÷adminÕÊ»§ºÍÃÜÂëµÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚϵͳÉÏÖ´ÐкÅÁî¡£
Ó°ÏìÁìÓò£º
VMware Workspace One Access 20.10 (Linux)
VMware Workspace One Access 20.01 (Linux)
VMware Identity Manager 3.3.3 (Linux)
VMware Identity Manager 3.3.2 (Linux)
VMware Identity Manager 3.3.1 (Linux)
VMware Identity Manager Connector 3.3.2, 3.3.1 (Linux)
VMware Identity Manager Connector 3.3.3, 3.3.2, 3.3.1 (Windows)
VMware Cloud Foundation
vRealize Suite Lifecycle Manager
0x02 ´ëÖý¨Òé
ĿǰVMwareÔÝδ°ä²¼Óйز¹¶¡£¬½¨Òé²Î¿¼Ò»Ê±½¨¸´Áìµ¼Êֲᾡ¿ì½¨¸´¡£
²úÆ· | °æ±¾ | ƽ̨ | CVE ID | ½¨¸´°æ±¾ | һʱ½¨¸´²½Öè |
Access | 20.10 | Linux | CVE-2020-4006 | ÔÝÎÞ²¹¶¡ | https://kb.vmware.com/s/article/81731 |
Access | 20.01 | Linux | CVE-2020-4006 | ||
vIDM | 3.3.3 | Linux | CVE-2020-4006 | ||
vIDM | 3.3.2 | Linux | CVE-2020-4006 | ||
vIDM | 3.3.1 | Linux | CVE-2020-4006 | ||
vIDM Connector | 3.3.3 | Windows | CVE-2020-4006 | ||
vIDM Connector | 3.3.2 | Linux | CVE-2020-4006 | ||
vIDM Connector | 3.3.2 | Windows | CVE-2020-4006 | ||
vIDM Connector | 3.3.1 | Linux | CVE-2020-4006 | ||
vIDM Connector | 3.3.1 | Windows | CVE-2020-4006 | ||
VMware Cloud Foundation£¨vIDM£© | 4.x | Any | CVE-2020-4006 | ||
vRealize Suite Lifecycle Manager (vIDM) | 8.x | Any | CVE-2020-4006 |
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0027.html
https://threatpost.com/vmware-zero-day-patch-pending/161523/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4006
0x04 ¹¦·òÏß
2020-11-23 VMware°ä²¼°²È«²¼¸æ
2020-11-24 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ