Vulnerability Description
VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Horizon Daas | >= 8.0.0, <= 8.0.1 |
Related Weaknesses (CWE)
References
- https://www.vmware.com/security/advisories/VMSA-2020-0021.htmlPatchVendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2020-0021.htmlPatchVendor Advisory
FAQ
What is CVE-2020-3977?
CVE-2020-3977 is a vulnerability with a CVSS score of 6.5 (MEDIUM). VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of t...
How severe is CVE-2020-3977?
CVE-2020-3977 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-3977?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Horizon Daas.