LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-4006: Multiple VMware Products Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-4006 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative…

CVE-2020-4006 is a command injection vulnerability in several VMware identity and access products: Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector. An attacker who can reach the administrative configurator on port 8443 and who already holds a valid configurator administrator password can run operating-system commands with unrestricted privileges. That combination turns a compromised admin credential into full host control, which is why identity-platform teams should treat this as a high-priority fix.

Public detail is limited to the products and access conditions above; exact version ranges, CVSS scores, and patch identifiers must be confirmed against the vendor advisory. CISA’s required action is simply to apply updates per vendor instructions. Ransomware use is not documented for this CVE.

How it works

The weakness is CWE-78 (OS command injection). In products of this class the administrative configurator accepts input that is later passed to a shell or system command without adequate sanitization. Once an attacker authenticates to the configurator interface, they can supply crafted values that cause the application to execute arbitrary commands as a privileged process on the underlying operating system.

Because the configurator is intended for setup and ongoing administration, it typically runs with elevated rights. Successful abuse therefore yields unrestricted OS-level execution rather than a limited application sandbox. No public exploit mechanics beyond the network-access-plus-valid-password precondition are supplied in the given facts; defenders should assume that any authenticated session to port 8443 is sufficient to attempt the injection and should verify the precise attack surface in the vendor advisory.

Am I affected? How to find it in your systems

These components commonly appear in enterprise identity, single-sign-on, and workspace environments—often as virtual appliances or connectors that bridge on-premises directories to cloud services. Inventory steps:

Telemetry that may indicate abuse includes unexpected processes spawned by the configurator service, shell or command-line activity originating from the appliance’s service accounts, and authentication successes to the configurator followed immediately by anomalous outbound connections or privilege-escalation artifacts. Because the attack requires a valid administrator password, also examine logs for configurator login failures or password-spray patterns preceding suspicious command execution.

How to remediate

Patch first. Apply the updates VMware published for the affected products exactly as described in the vendor advisory. CISA’s guidance is to follow those vendor instructions; no alternative remediation path is supplied in the facts.

After patching, harden the remaining attack surface common to this product class:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures shrink the window of opportunity but do not eliminate the underlying injection flaw; schedule the official update as soon as practicable.

If your data may have been exposed

Actively exploited command-injection flaws on identity infrastructure frequently lead to credential theft, lateral movement, and broader breaches. If you have reason to believe the configurator was reached by an unauthorized party, follow your incident-response plan: isolate the host, preserve logs, rotate all secrets that the appliance could have accessed, and examine downstream systems for follow-on activity. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated credentials have appeared in prior public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · Multiple Products
WeaknessCWE-78
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities