Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | VMware vCenter Server | vCenter Server 6.7 (embedded or external PSC) prior to 6.7u3f is affected by CVE-2020-3952 if it was upgraded from a previous release line such as 6.0 or 6.5. Clean installations of vCenter Server 6.7 (embedded or external PSC) are not affected. | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Vuln Check | https://github.com/commandermoon/CVE-2020-3952 | POC Details |
| 2 | Working Exploit PoC for VMWare vCenter Server (CVE-2020-3952) - Reverse Bind Shell | https://github.com/bb33bb/CVE-2020-3952 | POC Details |
| 3 | Exploit for CVE-2020-3952 in vCenter 6.7 | https://github.com/guardicore/vmware_vcenter_cve_2020_3952 | POC Details |
| 4 | VMWare vmdir missing access control exploit checker | https://github.com/gelim/CVE-2020-3952 | POC Details |
| 5 | Exploit for CVE-2020-3952 in vCenter 6.7 https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/ | https://github.com/Fa1c0n35/vmware_vcenter_cve_2020_3952 | POC Details |
| 6 | Vuln Check | https://github.com/chronoloper/CVE-2020-3952 | POC Details |
| 7 | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-3952.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-11694 | JetBrains PyCharm 信息泄露漏洞 | |
| CVE-2020-11647 | Wireshark BACapp dissector 注入漏洞 | |
| CVE-2015-9546 | Samsung移动设备路径遍历漏洞 | |
| CVE-2015-9547 | Samsung移动设备安全漏洞 | |
| CVE-2015-8546 | 多款Samsung产品缓冲区错误漏洞 | |
| CVE-2015-5524 | Samsung移动设备缓冲区错误漏洞 | |
| CVE-2020-6765 | D-Link DSL-GS225 J1 操作系统命令注入漏洞 | |
| CVE-2020-11669 | Linux kernel 安全漏洞 | |
| CVE-2020-1801 | Huawei Mate 30 Pro和Huawei Mate 30 授权问题漏洞 | |
| CVE-2020-1802 | 多款Huawei产品安全漏洞 |
No comments yet