Vulnerability record · CVE-2020-3952 · published 10 April 2020
CVE-2020-3952: VMware vCenter Server vmdir missing authentication access control flaw
Vmware · Vcenter Server
The vmdir service shipped with VMware vCenter Server, as part of an embedded or external Platform Services Controller, does not correctly implement access controls under certain conditions. This is a missing authentication flaw in a critical directory service, and it carries a critical CVSS score of 9.8, so it matters for any exposed vCenter deployment.
Description
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, KEV listing and very high EPSS probability make this an urgent patch target.
What it is
The vmdir service shipped with VMware vCenter Server, as part of an embedded or external Platform Services Controller, does not correctly implement access controls under certain conditions. This is a missing authentication flaw in a critical directory service, and it carries a critical CVSS score of 9.8, so it matters for any exposed vCenter deployment.
Impact
An unauthenticated network attacker can reach the affected vmdir functionality and gain full compromise of confidentiality, integrity and availability of the directory service. That can expose or alter directory data and, given vCenter's role, put managed infrastructure at risk.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw sits in vmdir as used by the embedded or external Platform Services Controller, so any network-reachable vCenter/PSC endpoint is in scope.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.90384 (99.8th percentile). Public exploit code is referenced via Packet Storm, so exploitation is both known and likely.
What to do
- Apply the VMware updates referenced in VMSA-2020-0006 as the first action.
- Restrict network access to vCenter Server and Platform Services Controller endpoints to trusted management networks only.
- Place vCenter/PSC behind management VLANs, VPN or jump hosts rather than exposing them to the internet.
- Audit vCenter and PSC deployments for the affected embedded or external PSC configuration and confirm patch level.
- Monitor for unexpected authentication or directory access attempts against vmdir.
Detection
- Review vmdir and vCenter authentication logs for successful access without prior authentication or anomalous directory queries.
- Hunt for network connections to vCenter/PSC management ports from untrusted or external source addresses.
- Correlate vCenter audit events with known exploit tooling behavior against the vmdir service.
- Alert on unexpected changes to vCenter directory objects or privilege assignments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3952 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware vCenter Server Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2020-0006 | Broken LinkVendor Advisory |
| http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2020-0006 | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3952 | US Government Resource |
Track CVE-2020-3952 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3952), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.