CVE-2014-4632
published 2015-02-01CVE-2014-4632: VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.62%
45.6th percentile
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xgg6-7q2q-mcm5: VMware vSphere Data Protection (VDP) 5
ghsa_unreviewed·2022-05-17
CVE-2014-4632 [MEDIUM] GHSA-xgg6-7q2q-mcm5: VMware vSphere Data Protection (VDP) 5
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.
VMware
VMware vSphere Data Protection product update addresses a certificate validation vulnerability.
vendor_vmware·2015-01-29·CVSS 4.3
CVE-2014-4632 [MEDIUM] VMware vSphere Data Protection product update addresses a certificate validation vulnerability.
VMSA-2015-0002: VMware vSphere Data Protection product update addresses a certificate validation vulnerability.
a. VMware vSphere Data Protection certificate validation vulnerability VMware vSphere Data Protection (VDP) does not fully validate SSL certificates coming from vCenter Server. This issue may allow a Man-in-the-Middle attack that enables the attacker to perform unauthorized backup and restore operations. VMware would like to thank Thorsten Tüllmann of the Steinbuch Centre for Computing, KIT, Germany for reporting this issue to VMware and the EMC Product Security Response Center for working with us on the issue. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2014-4632 to this issue. Column 4 of the following table lists the action
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2015-01/0154.htmlhttp://www.securitytracker.com/id/1031664http://www.vmware.com/security/advisories/VMSA-2015-0002.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/100866http://archives.neohapsis.com/archives/bugtraq/2015-01/0154.htmlhttp://www.securitytracker.com/id/1031664http://www.vmware.com/security/advisories/VMSA-2015-0002.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/100866
2015-02-01
Published