← Vulnerability feed

Vulnerability record · CVE-2020-4006 · published 23 November 2020

CVE-2020-4006: VMware Workspace ONE Access and Identity Manager command injection

Vmware · Identity Manager

VMware Workspace ONE Access, Access Connector, Identity Manager, and Identity Manager Connector contain an OS command injection flaw (CWE-78). A remote attacker with administrative privileges can inject commands that execute on the affected appliance, which matters because these components sit in the identity and access path of an environment.

9.1 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 17% · top 3.0% CWE-78 · OS command injection
9.1CVSS 3.1 base score, v2 9.0
17%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.1 critical severity, CISA KEV listing, and a high EPSS percentile indicate active exploitation risk in a sensitive identity component, though exploitation requires prior administrative access.

What it is

VMware Workspace ONE Access, Access Connector, Identity Manager, and Identity Manager Connector contain an OS command injection flaw (CWE-78). A remote attacker with administrative privileges can inject commands that execute on the affected appliance, which matters because these components sit in the identity and access path of an environment.

Impact

Successful exploitation lets the attacker run arbitrary commands on the underlying system with the privileges of the affected service, potentially leading to full compromise of the appliance and any credentials or trust relationships it holds.

Attack surface

Reachable over the network (AV:N) with no user interaction (UI:N), but the CVSS vector requires high privileges (PR:H), so the attacker must already hold an administrative account on the affected component. Scope is changed (S:C), meaning impact can extend beyond the vulnerable component.

Exploitation

CVE-2020-4006 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating exploitation in the wild; EPSS gives a 30-day probability of roughly 17.3 percent (96.9th percentile). No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor updates referenced in VMware advisory VMSA-2020-0027 as the primary fix.
  • If immediate patching is not possible, restrict network access to the affected Workspace ONE Access, Identity Manager, and connector management interfaces.
  • Audit and reduce the number of accounts with administrative privileges on these components, and enforce strong authentication for them.
  • Monitor CISA KEV guidance and confirm remediation by the listed due date of 2022-05-03.
  • Review the CERT/CC advisory VU#724367 for additional vendor guidance.

Detection

  • Monitor appliance and host logs for unexpected child processes or shell invocations spawned by the affected services.
  • Alert on command-injection patterns (shell metacharacters, encoded payloads) in requests to administrative endpoints of these components.
  • Baseline and review administrative account activity, especially command execution or configuration changes outside normal change windows.
  • Correlate outbound network connections from the affected appliances with known malicious infrastructure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-4006 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Multiple VMware Products Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2022-22954VMware Workspace ONE Access and Identity Manager server-side template injection RCEVMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-r…KEVEPSS 100%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed9.8CVE-2021-21972VMware vCenter Server plugin path traversal leads to remote code executionThe vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to u…KEVEPSS 100%analysed9.8CVE-2020-3992VMware ESXi OpenSLP use-after-free allows remote code executionOpenSLP as used in VMware ESXi contains a use-after-free flaw reachable over port 427 on the management network. An unauthenticated attacker with net…KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2020-4006), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.