CVE detail
CVE-2020-4008 — CVE-2020-4008
Published 2020-12-16 · Modified 2026-06-17 · Vendor vmware · Product carbon_black_cloud · Source nvd
LOW
severity
CVSS-derived band
0.0021
EPSS probability
exploitation probability, 30d
11.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References