Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:CTS:VMWARE-CDIR-CMD-INJ

Severity

Minor

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

VMWare Cloud Director Expression Language OS Command Injection

Release Date

2020/06/23

Update Number

3292

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: VMWare Cloud Director Expression Language OS Command Injection


This signature detects attempts to exploit a known vulnerability against VMware Cloud Director. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.

Affected Products

  • Vmware vcloud_director 10.0.0.0
  • Vmware vcloud_director 10.0.0.1
  • Vmware vcloud_director 9.1.0.0
  • Vmware vcloud_director 9.1.0.1
  • Vmware vcloud_director 9.1.0.2
  • Vmware vcloud_director 9.1.0.3
  • Vmware vcloud_director 9.1.0.4
  • Vmware vcloud_director 9.5.0.0
  • Vmware vcloud_director 9.5.0.1
  • Vmware vcloud_director 9.5.0.2
  • Vmware vcloud_director 9.5.0.3
  • Vmware vcloud_director 9.5.0.4
  • Vmware vcloud_director 9.5.0.5
  • Vmware vcloud_director 9.7.0.0
  • Vmware vcloud_director 9.7.0.1
  • Vmware vcloud_director 9.7.0.2
  • Vmware vcloud_director 9.7.0.3
  • Vmware vcloud_director 9.7.0.4

References

  • CVE: CVE-2020-3956

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out