Government Operations

REI INSIGHTS

Explore Our Insights

CISA Issues Emergency Directive to Mitigate Vulnerabilities Over VMware Products

CISA Issues Emergency Directive to Mitigate Vulnerabilities Over VMware Products

Reading Time: 2 minutesCISA issued an Emergency Directive requiring Federal Civilian Executive Branch (FCEB) agencies with certain VMware products connected to the internet to act as if they’ve been compromised. CISA directed that any FCEB agencies leveraging the following VMware products initiate threat hunting activities using active detection methods provided in the Cybersecurity Advisory (CSA) issued by CISA. The Authentication Bypass vulnerability impacting VMware Workspace ONE Access, Identity Manager, and vRealize Automation has resulted in a maximum CVSSv3 base score of 9.8. REI has determined that these vulnerabilities pose an unacceptable risk to FCEB agencies and require emergency action.