Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cvrp-6cg2-w64m

Опубликовано: 21 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.

EPSS

Процентиль: 65%
0.00498
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.

CVSS3: 7.2
fstec
около 4 лет назад

Уязвимость компонента VMware Verify платформы администрирования приложений Workspace ONE Access, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 65%
0.00498
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287