CVE-2018-6960

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
20/04/2018
Last modified:
22/05/2018

Description

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:horizon_daas:*:*:*:*:*:*:*:* 7.0.0 (including) 8.0.0 (excluding)