QID 373511

QID 373511: VMware Horizon DaaS Broken Authentication Vulnerability (VMSA-2020-0021)

Horizon DaaS is a piece of software delivered by VMware to offer a multi-tenant VDI product used mainly by Service Providers.

Horizon DaaS contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Affected Versions:
VMWare Horizon DaaS 7.x, 8.x prior to 8.0.1 Update 1*


*This update applies to 8.0.1 only. QID Detection Logic (Authenticated):

Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Vmware has released patch for VMware Horizon DaaS.
    Refer to VMware advisory VMSA-2020-0021 for more information.

    CVEs related to QID 373511

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2020-0021 URL Logo www.vmware.com/security/advisories/VMSA-2020-0021.html