Critical severity9.1CISA KEVNVD Advisory· Published Nov 23, 2020· Updated Jun 17, 2026
CVE-2020-4006
CVE-2020-4006
Description
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:vmware:cloud_foundation:4.0.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vmware:cloud_foundation:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:cloud_foundation:4.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.1:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:vmware:identity_manager:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:identity_manager:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:*
- (no CPE)
cpe:2.3:a:vmware:identity_manager_connector:3.3.1:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:vmware:identity_manager_connector:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:identity_manager_connector:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:identity_manager_connector:3.3.3:*:*:*:*:*:*:*
- (no CPE)
cpe:2.3:a:vmware:one_access:20.01:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vmware:one_access:20.01:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:one_access:20.10:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:*:*:*:*:*:*:*:*Range: >=8.0,<=8.2
- VMware/Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connectordescription
Patches
Vulnerability mechanics
References
3- www.kb.cert.org/vuls/id/724367nvdThird Party AdvisoryUS Government Resource
- www.vmware.com/security/advisories/VMSA-2020-0027.htmlnvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.