Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
Published: 2020-04-10
VMware patches a critical information disclosure flaw in vCenter Server with a CVSSv3 score of 10.0. Background On April 9, VMware published VMSA-2020-0006, a security advisory for a critical vulnerability in vCenter Server that received the maximum CVSSv3 score of 10.0.
https://www.vmware.com/security/advisories/VMSA-2020-0006
http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authentication-Bypass.html