← Back to browse · API

CVE-2020-3952

Severity
CRITICAL
CVSS
9.8
EPSS
0.90384
Risk score
56.63
CISA KEV
Yes
PoC
Yes
Published
2020-04-10
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-25217, GHSA-RQPW-V3G2-QCCX
Products
VMware:vCenter Server, n/a:VMware vCenter Server vCenter Server 6.7 (embedded or external PSC) prior to 6.7u3f is affected by CVE-2020-3952 if it was upgraded from a previous release line such as 6.0 or 6.5. Clean installations of vCenter Server 6.7 (embedded or external PSC) are not affected.
Sources
cisa.gov CVE-2020-3952
github 47ab4532833bba00955f751e|CVE-2020-3952
euvd EUVD-2020-25217

Description

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

References