CVE-2017-4917
published 2017-06-07CVE-2017-4917: VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow…
PriorityP343critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.84%
53.6th percentile
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
| vmware | vsphere_data_protection | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
vSphere Data Protection (VDP) updates address multiple security issues.
vendor_vmware·2017-06-06·CVSS 9.8
CVE-2017-4914 [CRITICAL] vSphere Data Protection (VDP) updates address multiple security issues.
VMSA-2017-0010: vSphere Data Protection (VDP) updates address multiple security issues.
a. VDP Java deserialization issue VDP contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance. VMware would like to thank Tim Roberts, Arthur Chilipweli, and Kelly Correll from NTT Security for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4914 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/ Apply Patch Mitigation/ Workaround VMware ProductVDP Product Version6.1.x Running on VA SeverityCr
GHSA
GHSA-mrgm-rp63-hxmr: VMware vSphere Data Protection (VDP) 6
ghsa_unreviewed·2022-05-13
CVE-2017-4917 [CRITICAL] CWE-327 GHSA-mrgm-rp63-hxmr: VMware vSphere Data Protection (VDP) 6
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-06-07
Published