VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate.
2021-06-23T12:15:07.857
2024-11-21T05:49:24.780
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | carbon_black_app_control | < 8.5.8 | Yes |
Application | vmware | carbon_black_app_control | < 8.6.2 | Yes |
Application | vmware | carbon_black_app_control | 8.0 | Yes |
Application | vmware | carbon_black_app_control | 8.1 | Yes |