← Vulnerability feed

Vulnerability record · CVE-2020-3952 · published 10 April 2020

CVE-2020-3952: VMware vCenter Server vmdir missing authentication access control flaw

Vmware · Vcenter Server

The vmdir service shipped with VMware vCenter Server, as part of an embedded or external Platform Services Controller, does not correctly implement access controls under certain conditions. This is a missing authentication flaw in a critical directory service, and it carries a critical CVSS score of 9.8, so it matters for any exposed vCenter deployment.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 90% · top 0.2% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 6.8
90%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, KEV listing and very high EPSS probability make this an urgent patch target.

What it is

The vmdir service shipped with VMware vCenter Server, as part of an embedded or external Platform Services Controller, does not correctly implement access controls under certain conditions. This is a missing authentication flaw in a critical directory service, and it carries a critical CVSS score of 9.8, so it matters for any exposed vCenter deployment.

Impact

An unauthenticated network attacker can reach the affected vmdir functionality and gain full compromise of confidentiality, integrity and availability of the directory service. That can expose or alter directory data and, given vCenter's role, put managed infrastructure at risk.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw sits in vmdir as used by the embedded or external Platform Services Controller, so any network-reachable vCenter/PSC endpoint is in scope.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.90384 (99.8th percentile). Public exploit code is referenced via Packet Storm, so exploitation is both known and likely.

What to do

  • Apply the VMware updates referenced in VMSA-2020-0006 as the first action.
  • Restrict network access to vCenter Server and Platform Services Controller endpoints to trusted management networks only.
  • Place vCenter/PSC behind management VLANs, VPN or jump hosts rather than exposing them to the internet.
  • Audit vCenter and PSC deployments for the affected embedded or external PSC configuration and confirm patch level.
  • Monitor for unexpected authentication or directory access attempts against vmdir.

Detection

  • Review vmdir and vCenter authentication logs for successful access without prior authentication or anomalous directory queries.
  • Hunt for network connections to vCenter/PSC management ports from untrusted or external source addresses.
  • Correlate vCenter audit events with known exploit tooling behavior against the vmdir service.
  • Alert on unexpected changes to vCenter directory objects or privilege assignments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3952 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware vCenter Server Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3952 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2023-34048VMware vCenter Server DCERPC out-of-bounds writevCenter Server contains an out-of-bounds write in its DCERPC protocol implementation. A remote, unauthenticated attacker with network access can trig…KEVEPSS 99%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed9.8CVE-2021-21972VMware vCenter Server plugin path traversal leads to remote code executionThe vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to u…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-3952), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.