Privilege Escalation Vulnerability in VMware SD-WAN Orchestrator
CVE-2020-3985
8.8HIGH
What is CVE-2020-3985?
A flaw in the VMware SD-WAN Orchestrator allows authenticated users to manipulate access levels by exploiting a vulnerable API, potentially leading to unauthorized system access. This issue affects versions 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4, and highlights the necessity for implementing adequate access controls and API security measures to prevent misuse.
Affected Version(s)
VMware SD-WAN Orchestrator VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4.