← Vulnerability feed

Vulnerability record · CVE-2020-4001 · published 24 November 2020

CVE-2020-4001: Vmware sd-wan orchestrator insecure default initialization vulnerability

Vmware · Sd Wan Orchestrator

The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.

9.8 CVSS 3.1 Critical EPSS 2.9% · top 13.6% CWE-1188 · Insecure default initialization
9.8CVSS 3.1 base score, v2 7.5
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4001 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-3985Vmware sd-wan orchestrator vulnerabilityThe SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privileg…EPSS 1.4%8.8CVE-2020-4000Vmware sd-wan orchestrator path traversal vulnerabilityThe SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversa…EPSS 43%7.2CVE-2020-4002Vmware sd-wan orchestrator vulnerabilityThe SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An auth…EPSS 1.6%6.5CVE-2020-3984Vmware sd-wan orchestrator sql injection vulnerabilityThe SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An a…EPSS 22%6.5CVE-2020-4003Vmware sd-wan orchestrator sql injection vulnerabilityVMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attack…EPSS 1.2%5.3CVE-2025-48927TeleMessage Spring Boot Actuator heap dump endpoint exposed by insecure defaultTeleMessage through 2025-05-05 ships with Spring Boot Actuator configured to expose the /heapdump endpoint. Because this is an insecure default initi…KEVEPSS 11%analysed9.8CVE-2023-27524Apache Superset default SECRET_KEY allows session forgery and auth bypassApache Superset versions up to and including 2.0.1 ship with a default SECRET_KEY that, if left unchanged, lets an attacker forge signed session cook…KEVEPSS 97%analysed9.8CVE-2023-6448Unitronics VisiLogic default admin password in Vision and Samba PLCs/HMIsUnitronics VisiLogic before 9.9.00, used with Vision and Samba PLCs and HMIs, ships with a default administrative password. Because the credential is…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2020-4001), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.