Moderate

VMSA-2020-0021
6.3
2020-09-22
2020-09-22 (Initial Advisory)
CVE-2020-3977
Horizon DaaS update addresses a broken authentication vulnerability (CVE-2020-3977)
1. Impacted Products
  • VMware Horizon DaaS (Horizon DaaS)
2. Introduction

A broken authentication vulnerability affecting VMware Horizon DaaS was privately reported to VMware. Updates are available to address this vulnerability in affected VMware product.

3. Broken authentication vulnerability (CVE-2020-3977)

Description

Horizon DaaS contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.3.

Known Attack Vectors

Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process.

 

Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

Resolution

To remediate CVE-2020-3977 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' below.

Workarounds

None.

Additional Documentation

None.

Notes

In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.   

Acknowledgements

VMware would like to thank David Roccasalva of Privasec for reporting this issue to us.

Response Matrix

Product Version Running On CVE Identifier CVSSv3 Severity Fixed Version Workarounds Additional Documentation
Horizon DaaS
9.x
Any
CVE-2020-3977
N/A
N/A
not affected
N/A
N/A
Horizon DaaS
7.x, 8.x
Any
CVE-2020-3977
moderate
None
None

**This update applies to 8.0.1 only. Please see the download link for more information.

4. References
5. Change Log

2020-09-22 VMSA-2020-0021
Initial security advisory.

6. Contact

E-mail list for product security notifications and announcements:

https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce 

 

This Security Advisory is posted to the following lists:  

security-announce@lists.vmware.com

 

E-mail: security@vmware.com

PGP key at:

https://kb.vmware.com/kb/1055 

 

VMware Security Advisories

https://www.vmware.com/security/advisories 

 

VMware Security Response Policy

https://www.vmware.com/support/policies/security_response.html 

 

VMware Lifecycle Support Phases

https://www.vmware.com/support/policies/lifecycle.html 

 

VMware Security & Compliance Blog  

https://blogs.vmware.com/security 

 

Twitter

https://twitter.com/VMwareSRC

 

Copyright 2020 VMware Inc. All rights reserved.