← KEV catalog
CISA known exploited vulnerability

CVE-2020-3992

VMware ESXi OpenSLP Use-After-Free Vulnerability

SOURCE FACT

VMware · ESXi

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2020-3992

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?