CVE-2019-5534Sensitive Information Exposure in Vmware Vcenter Server

Severity
7.7HIGHNVD
EPSS
0.4%
top 41.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Latest updateMay 24

Description

VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig properties. A malicious actor with access to query the vAppConfig properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 3.1 | Impact: 4.0

Affected Packages2 packages

CVEListV5vmware/vcenter_server6.0 prior to 6.0 U3j, 6.5 prior to 6.5 U3, 6.7 prior to 6.7 U3+2
NVDvmware/vcenter_server6.0, 6.5, 6.7+2

🔴Vulnerability Details

2
GHSA
GHSA-7cjg-pprv-8vg9: VMware vCenter Server (62022-05-24
CVEList
CVE-2019-5534: VMware vCenter Server (62019-09-18

📋Vendor Advisories

1
VMware
VMware ESXi and vCenter Server updates address command injection and information disclosure vulnerabilities. (CVE-2017-16544, CVE-2019-5531, CVE-2019-5532, CVE-2019-5534)2019-09-16
CVE-2019-5534 — Sensitive Information Exposure | cvebase