Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-564r-7p67-986w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

EPSS

Процентиль: 31%
0.00119
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость программного обеспечения для развертывания виртуальных компьютеров и приложений Vmware Horizon DaaS, позволяющая нарушителю обойти процесс двухфакторной аутентификации

EPSS

Процентиль: 31%
0.00119
Низкий