Vulnerability record · CVE-2020-4006 · published 23 November 2020
CVE-2020-4006: VMware Workspace ONE Access and Identity Manager command injection
Vmware · Identity Manager
VMware Workspace ONE Access, Access Connector, Identity Manager, and Identity Manager Connector contain an OS command injection flaw (CWE-78). A remote attacker with administrative privileges can inject commands that execute on the affected appliance, which matters because these components sit in the identity and access path of an environment.
Description
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.1 critical severity, CISA KEV listing, and a high EPSS percentile indicate active exploitation risk in a sensitive identity component, though exploitation requires prior administrative access.
What it is
VMware Workspace ONE Access, Access Connector, Identity Manager, and Identity Manager Connector contain an OS command injection flaw (CWE-78). A remote attacker with administrative privileges can inject commands that execute on the affected appliance, which matters because these components sit in the identity and access path of an environment.
Impact
Successful exploitation lets the attacker run arbitrary commands on the underlying system with the privileges of the affected service, potentially leading to full compromise of the appliance and any credentials or trust relationships it holds.
Attack surface
Reachable over the network (AV:N) with no user interaction (UI:N), but the CVSS vector requires high privileges (PR:H), so the attacker must already hold an administrative account on the affected component. Scope is changed (S:C), meaning impact can extend beyond the vulnerable component.
Exploitation
CVE-2020-4006 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating exploitation in the wild; EPSS gives a 30-day probability of roughly 17.3 percent (96.9th percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the vendor updates referenced in VMware advisory VMSA-2020-0027 as the primary fix.
- If immediate patching is not possible, restrict network access to the affected Workspace ONE Access, Identity Manager, and connector management interfaces.
- Audit and reduce the number of accounts with administrative privileges on these components, and enforce strong authentication for them.
- Monitor CISA KEV guidance and confirm remediation by the listed due date of 2022-05-03.
- Review the CERT/CC advisory VU#724367 for additional vendor guidance.
Detection
- Monitor appliance and host logs for unexpected child processes or shell invocations spawned by the affected services.
- Alert on command-injection patterns (shell metacharacters, encoded payloads) in requests to administrative endpoints of these components.
- Baseline and review administrative account activity, especially command execution or configuration changes outside normal change windows.
- Correlate outbound network connections from the affected appliances with known malicious infrastructure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-4006 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Multiple VMware Products Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2020-0027.html | Vendor Advisory |
| https://www.kb.cert.org/vuls/id/724367 | Third Party AdvisoryUS Government Resource |
| https://www.vmware.com/security/advisories/VMSA-2020-0027.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-4006 | US Government Resource |
Track CVE-2020-4006 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-4006), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.