CyberSec.Space Logo
返回 CVE 浏览器

CVE-2020-3992

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score29.9880%
EPSS Percentile85.38th
Published2020-10-20
Last Modified2025-10-30
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

Affected Platforms (CPE)

📦
Vmware

Cloud Foundation

>= 3.0 and < 3.10.1.2>= 4.0 and < 4.1.0.1
💻
Vmware

Esxi

= 6.5= 6.7= 7.0.0

References & Advisories

相關資安分析文章

相关漏洞威胁

CVE-2020-3992 Detail & Impact Analysis | CVSS 9.8 (CRITICAL) | Cyber-Sec.Space | Cyber-Sec.Space