6.5
CVSSv3

CVE-2020-3977

Published: 22/09/2020 Updated: 30/09/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

VMware Horizon DaaS (7.x and 8.x prior to 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an malicious user to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware horizon daas 7.0.0

vmware horizon daas