cbcvebase.
CVE-2014-4632
published 2015-02-01

CVE-2014-4632: VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition…

PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.62%
45.6th percentile
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.

Affected

8 ranges
VendorProductVersion rangeFixed in
vmwarevcenter_server
vmwarevmware_vsphere
vmwarevsphere_data_protection
vmwarevsphere_data_protection
vmwarevsphere_data_protection
vmwarevsphere_data_protection
vmwarevsphere_data_protection
vmwarevsphere_data_protection
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.