CVE-2014-4632

CWE-3103 documents3 sources
Severity
4.3MEDIUM
EPSS
0.1%
top 65.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 17

Description

VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-xgg6-7q2q-mcm5: VMware vSphere Data Protection (VDP) 52022-05-17
CVEList
CVE-2014-4632: VMware vSphere Data Protection (VDP) 52015-02-01