VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Published: 2020-12-09
The National Security Agency warns that Russian state-sponsored threat actors are exploiting an important VMware vulnerability in the wild. Background On December 7, the National Security Agency (NSA) published a cybersecurity advisory regarding in-the-wild exploitation, by Russian state-sponsored threat actors, of a vulnerability in several VMware products.
https://www.infosecurity-magazine.com/news/broadcom-patches-vmware-nsx-vcenter/
https://www.tenable.com/cyber-exposure/2020-threat-landscape-retrospective
https://media.defense.gov/2020/Dec/07/2002547071/-1/-1/0/CSA_VMWARE%20ACCESS_U_OO_195076_20.PDF