LDAP: VMware vCenter vmdir VmDirLegacyAccessCheck Remote Code Execution

This signature detects attempts to exploit a known vulnerability against VMware vCenter. A successful attack can lead to arbitrary code execution.

Extended Description

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

Affected Products

Vmware vcenter_server

References

CVE: CVE-2020-3952

Short Name
LDAP:VMWARE-VCENTER-RCE
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
LDAP
Keywords
CVE-2020-3952 Code Execution Remote VMware VmDirLegacyAccessCheck vCenter vmdir
Release Date
05/19/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3539
False Positive
Unknown
Vendors

Vmware

CVSS Score

6.8

Found a potential security threat?