Information disclosure in Broadcom products - CVE-2020-3940

 

Information disclosure in Broadcom products - CVE-2020-3940

Published: January 10, 2020


Vulnerability identifier: #VU24188
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3940
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected software does not properly handle certificate verification failures if SSL Pinning has been enabled in the Workspace ONE UEM Console. A remote attacker with man-in-the-middle (MITM) network positioning between an affected mobile application and Workspace ONE UEM Device Services can capture sensitive data in transit if SSL Pinning is enabled.


Affected software

Workspace ONE People
Workspace ONE Notebook
Workspace ONE PIV-D
Workspace ONE Content for Android
Workspace ONE Content for iOS
Workspace ONE Boxer
Workspace ONE Web
Workspace ONE Intelligent Hub
Workspace ONE SDK Plugin for Xamarin
Workspace ONE SDK Plugin for Apache Cordova
Workspace ONE SDK (Objective-C)
Workspace ONE SDK

How to mitigate CVE-2020-3940

Install updates from vendor's website.

Workspace ONE People - update to 1.3.2
Workspace ONE Notebook - update to 1.2.1
Workspace ONE SDK Plugin for Xamarin - update to 1.4.1
Workspace ONE PIV-D - update to 1.4.2
Workspace ONE SDK Plugin for Apache Cordova - update to 1.5.1
Workspace ONE Content for Android - update to 3.21
Workspace ONE Content for iOS - update to 4.20
Workspace ONE SDK (Objective-C) - update to 5.9.9.8​
Workspace ONE Boxer - update to 5.13.1
Workspace ONE Web - update to 7.10.8
Workspace ONE SDK - update to 19.11.1
Workspace ONE Intelligent Hub - update to 19.11.1

External References

Related Security Bulletins