Vulnerabilities
Vulnerable Software
Vmware:  >> Horizon Daas  >> 8.0.1  Security Vulnerabilities
VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.
CVSS Score
6.5
EPSS Score
0.001
Published
2020-09-22
CVE-2019-5544
Known exploited
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVSS Score
9.8
EPSS Score
0.871
Published
2019-12-06


Contact Us

Shodan ® - All rights reserved