November 3, 2021 · Applied Cybernetics Group
CVE-2020-3952 — VMware vCenter Server
VMware vCenter Server Information Disclosure Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- VMware
- Product
- vCenter Server
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-3952
CISA short description
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
Required action
Apply updates per vendor instructions.