CVE-2019-5532
published 2019-09-18CVE-2019-5532: VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging…
PriorityP343high7.7CVSS 3.1
AVNACLPRLUINSCCHINAN
EPSS
1.86%
76.8th percentile
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4v8m-3x8w-h83j: VMware vCenter Server (6
ghsa_unreviewed·2022-05-24
CVE-2019-5532 [HIGH] CWE-522 GHSA-4v8m-3x8w-h83j: VMware vCenter Server (6
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).
VMware
VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534)
vendor_vmware·2019-09-16·CVSS 8.8
CVE-2017-16544 [HIGH] VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534)
VMSA-2019-0013: VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534)
| Advisory Severity | Important | CVSSv3 Range | 4.2-7.7 | Synopsis | VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534) | Issue Date | 2019-09-16 | Updated On | 2019-09-19 | CVE(s) | CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534 VMware vSphere ESXi (ESXi) VMware vCenter Server (vCenter) 2. IntroductionESXi and vCenter updates address multiple vulnerabilities.
CVEs: CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534
Affected products: VMware ESXi, VMware vCenter S
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-18
Published