QID 730401
Date Published: 2022-03-16
QID 730401: VMware Carbon Black App Control Improper Authentication Vulnerability (VMSA-2021-0012)
VMware Carbon Black App Control is an application allow listing solution that is designed to enable security operations teams to lock down new and legacy systems against unwanted change, simplify the compliance process, and provide protection for corporate systems.
Affected Versions(s):
VMware Carbon Black App Control v8.0.x, 8.1.x
VMware Carbon Black App Control v8.5.x before v8.5.8
VMware Carbon Black App Control v8.6.x before v8.6.2
QID Detection Logic
This QID sends the GET request to login.php and checks for vulnerable version.
Note: The QID is marked practice as their is no check for the Hotfix.
A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate.
- VMSA-2021-0012 -
www.vmware.com/security/advisories/VMSA-2021-0012.html
CVEs related to QID 730401
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2021-0012 |
|