
====================================================================

                             CERT-Renater

                 Note d'Information No. 2020/VULN532
_____________________________________________________________________

DATE                : 22/09/2020

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running VMware Horizon DaaS (Horizon DaaS)
                        versions 7.x, 8.x prior to 8.0.1 Update 1**.

=====================================================================
https://www.vmware.com/security/advisories/VMSA-2020-0021.html
_____________________________________________________________________


Moderate


Advisory ID:        VMSA-2020-0021
CVSSv3 Range:       6.3
Issue Date:         2020-09-22
Updated On:         2020-09-22 (Initial Advisory)
CVE(s):             CVE-2020-3977


Synopsis:
Horizon DaaS update addresses a broken authentication vulnerability
(CVE-2020-3977)


1. Impacted Products

    VMware Horizon DaaS (Horizon DaaS)


2. Introduction

A broken authentication vulnerability affecting VMware Horizon DaaS was
privately reported to VMware. Updates are available to address this
vulnerability in affected VMware product.


3. Advisory Details

Description

Horizon DaaS contains a broken authentication vulnerability due to a
flaw in the way it handled the first factor authentication. VMware has
evaluated the severity of this issue to be in the Moderate severity
range with a maximum CVSSv3 base score of 6.3.

Known Attack Vectors

Successful exploitation of this issue may allow an attacker to bypass
two-factor authentication process.


Note: In order to exploit this issue, an attacker must have a legitimate
account on Horizon DaaS.


Resolution

To remediate CVE-2020-3977 apply the patches listed in the 'Fixed
Version' column of the 'Response Matrix' below.


Workarounds

None.


Additional Documentation

None.


Notes

In order to exploit this issue, an attacker must have a legitimate
account on Horizon DaaS.


Acknowledgements

VMware would like to thank David Roccasalva of Privasec for reporting
this issue to us.


Response Matrix

Product 	Version 	Running On 	CVE Identifier 	CVSSv3 	Severity 	Fixed
Version 	Workarounds 	Additional Documentation

Horizon DaaS    9.x         Any         CVE-2020-3977      N/A     N/A
	not affected       N/A          N/A

Horizon DaaS    7.x, 8.x    Any        CVE-2020-3977     6.3
	moderate        8.0.1 Update 1**     None       None

**This update applies to 8.0.1 only. Please see the download link for
more information.


4. References

Fixed Version(s) and Release Notes:


Horizon DaaS 8.0.1 Update 1

Downloads and Documentation:
https://my.vmware.com/web/vmware/downloads/details?downloadGroup=HORIZON_DAAS_801&productId=743&rPId=36148
https://docs.vmware.com/en/VMware-Horizon-DaaS/services/rn/Horizon-DaaS-801-Release-Notes.html#rollup


Mitre CVE Dictionary Links:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3977


FIRST CVSSv3 Calculator:
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L


5. Change Log

2020-09-22 VMSA-2020-0021
Initial security advisory.


6. Contact

E-mail list for product security notifications and announcements:
https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce


This Security Advisory is posted to the following lists:
security-announce@lists.vmware.com


E-mail: security@vmware.com

PGP key at:
https://kb.vmware.com/kb/1055



VMware Security Advisories
https://www.vmware.com/security/advisories


VMware Security Response Policy
https://www.vmware.com/support/policies/security_response.html


VMware Lifecycle Support Phases
https://www.vmware.com/support/policies/lifecycle.html


VMware Security & Compliance Blog
https://blogs.vmware.com/security


Twitter
https://twitter.com/VMwareSRC



Copyright 2020 VMware Inc. All rights reserved.


=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================




