HomeSecurityVMware Cloud Director: Error allows access to infrastructure!

VMware Cloud Director: Error allows access to infrastructure!

Recently, security researchers at Citadelo have uncovered a new flaw in VMware Cloud Director, a leading platform , that could allow an attacker to access sensitive data and control private clouds within an infrastructure. The security researchers have flagged the flaw, identified as CVE-2020-3956, claiming that it is a typical code that leads to malicious code injection or insertion.

This security flaw could be exploited by attackers to send malicious traffic to Cloud Director, leading to arbitrary code execution. Furthermore, this security flaw, which was discovered by researchers and has a severity rating of 8.8 out of 10, is quite dangerous. VMware Cloud Director is a popular distribution platform used to manage and organize cloud resources, allowing companies to access data centers distributed across different geographical regions.

VMware Cloud Director: Error allows access to infrastructure!

In other words, attackers can exploit this flaw to launch code execution attacks and technically take over all private clouds connected to the provided infrastructure. Security firm Citadelo discovered this flaw on April 1st, after conducting a security audit for one of its clients. However, since this tool is used by many companies worldwide, it made the issue quite critical and urgent. This security flaw affects VMware Cloud Director versions 10.1.0 and earlier, as well as vCloud Director 8x – 10x on Linux and PhotonOS devices. Furthermore, this flaw could be exploited via HTML5, Flex-based UIs, API Explorer interface, and API access. The following are affected by this security flaw:

  • Public cloud providers using VMware vCloud Director.
  • Private cloud providers using VMware vCloud Director.
  • Businesses using VMware vCloud Director technology.
  • Any government agency using VMware Cloud Director.

This security flaw allows attackers to do the following:

  • To see all the critical content of a system's internal database.
  • Modify the database to access virtual machines (VMs) assigned to different organizations.
  • Escalation of privileges from “Organization Administrator” to “System Administrator”, with access to all cloud accounts.
  • Change the Cloud Director login page.
  • Gain access to other sensitive data, such as full names, email , and IP addresses of customers.
  • By exploiting code injection vulnerabilities, attackers can view confidential data in internal databases, such as passwords given to customers of the information system.

However, following these discoveries, security researchers directly shared their findings on VMware's official website, and the company quickly responded to fix the security flaws with a series of updates to versions 9.1.0.4, 9.5.0.6, 9.7.0.5, and 10.0.0.2. Therefore, organizations that have not yet applied this patch are still vulnerable to this bug.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS