QID 373511
QID 373511: VMware Horizon DaaS Broken Authentication Vulnerability (VMSA-2020-0021)
Horizon DaaS is a piece of software delivered by VMware to offer a multi-tenant VDI product used mainly by Service Providers.
Horizon DaaS contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication.
Affected Versions:
VMWare Horizon DaaS 7.x, 8.x prior to 8.0.1 Update 1*
*This update applies to 8.0.1 only.
QID Detection Logic (Authenticated):
Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process.
Solution
Vmware has released patch for VMware Horizon DaaS.
Refer to VMware advisory VMSA-2020-0021 for more information.
Refer to VMware advisory VMSA-2020-0021 for more information.
Vendor References
- VMSA-2020-0021 -
www.vmware.com/security/advisories/VMSA-2020-0021.html
CVEs related to QID 373511
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2020-0021 |
|