CVE-2020-4006 | VMwareºÅÁî×¢Èë·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-11-24

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2020-4006

ʱ    ¼ä

2020-10-24

Àà    ÐÍ

ºÅÁî×¢Èë

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

 

image.png

 

2020Äê11ÔÂ23ÈÕ£¬VMware°ä²¼°²È«²¼¸æ£¬Æä¶à¸ö²úÆ·ºÍ×é¼þµÄÖÎÀíÅäÖÃÆ÷ÖдæÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¨CVE-2020-4006£©£¬ÆäCVSSÆÀ·Ö9.1¡£

ÓµÓÐÖÎÀíÅäÖÃÆ÷8443¶Ë¿ÚµÄÍøÂç½Ó¼ûȨÏÞ²¢Õ¼ÓÐÖÎÀíÅäÖÃÆ÷adminÕÊ»§ºÍÃÜÂëµÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚϵͳÉÏÖ´ÐкÅÁî¡£


Ó°ÏìÁìÓò£º

VMware Workspace One Access 20.10 (Linux)

VMware Workspace One Access 20.01 (Linux)

VMware Identity Manager 3.3.3 (Linux)

VMware Identity Manager 3.3.2 (Linux)

VMware Identity Manager 3.3.1 (Linux)

VMware Identity Manager Connector 3.3.2, 3.3.1 (Linux)

VMware Identity Manager Connector 3.3.3, 3.3.2, 3.3.1 (Windows)

VMware Cloud Foundation

vRealize Suite Lifecycle Manager

 

0x02 ´ëÖý¨Òé

ĿǰVMwareÔÝδ°ä²¼Óйز¹¶¡£¬½¨Òé²Î¿¼Ò»Ê±½¨¸´Áìµ¼Êֲᾡ¿ì½¨¸´¡£

²úÆ·

°æ±¾

ƽ̨

CVE ID

½¨¸´°æ±¾

һʱ½¨¸´²½Öè

Access

20.10

Linux

CVE-2020-4006

ÔÝÎÞ²¹¶¡

https://kb.vmware.com/s/article/81731

Access

20.01

Linux

CVE-2020-4006

vIDM

3.3.3

Linux

CVE-2020-4006

vIDM

3.3.2

Linux

CVE-2020-4006

vIDM

3.3.1

Linux

CVE-2020-4006

vIDM Connector

3.3.3

Windows

CVE-2020-4006

vIDM Connector

3.3.2

Linux

CVE-2020-4006

vIDM Connector

3.3.2

Windows

CVE-2020-4006

vIDM Connector

3.3.1

Linux

CVE-2020-4006

vIDM Connector

3.3.1

Windows

CVE-2020-4006

VMware Cloud Foundation£¨vIDM£©

4.x

Any

CVE-2020-4006

vRealize Suite Lifecycle Manager   (vIDM)

8.x

Any

CVE-2020-4006

 

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2020-0027.html

https://threatpost.com/vmware-zero-day-patch-pending/161523/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4006

 

0x04 ¹¦·òÏß

2020-11-23  VMware°ä²¼°²È«²¼¸æ

2020-11-24  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png