CVE-2020-3952CISA KEVEPSS p99.8%

CVE-2020-3952VMware vCenter Server Information Disclosure Vulnerability

VMware / vCenter Server

Description

VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.

Scoring

EPSS90.38% probability of exploitation · percentile 99.8% · 2026-06-15T12:03:41Z

CISA KEV entry

Added to KEV: 2021-11-03

(incoming)1

TypeTargetConfidenceTier
KEVEntryVMware vCenter Server Information Disclosure Vulnerabilitykev-cve-2020-39520%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
VMware vCenter Server Incorrect Default File Permissions Vulnerability
CVE
VMware vCenter Server Remote Code Execution Vulnerability
CVE
VMware vCenter Server File Upload Vulnerability
CVE
VMware vCenter Server Privilege Escalation Vulnerability
CVE
VMware vCenter Server Improper Access Control
CVE
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.