CVE-2019-5537
published 2019-10-28CVE-2019-5537: Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware…
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.65%
47.2th percentile
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over FTPS and HTTPS. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup target may be able to intercept sensitive data in transit during File-Based Backup and Restore operations.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5w52-qrhj-grg8: Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of
ghsa_unreviewed·2022-05-24
CVE-2019-5537 [MEDIUM] CWE-295 GHSA-5w52-qrhj-grg8: Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over FTPS and HTTPS. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup target may be able to intercept sensitive data in transit during File-Based Backup and Restore operations.
VMware
VMware vCenter Server Appliance updates address sensitive information disclosure vulnerability in backup and restore functions (CVE-2019-5537, CVE-2019-5538)
vendor_vmware·2019-10-24·CVSS 5.9
CVE-2019-5537 [MEDIUM] VMware vCenter Server Appliance updates address sensitive information disclosure vulnerability in backup and restore functions (CVE-2019-5537, CVE-2019-5538)
VMSA-2019-0018: VMware vCenter Server Appliance updates address sensitive information disclosure vulnerability in backup and restore functions (CVE-2019-5537, CVE-2019-5538)
| Advisory Severity | Moderate | Synopsis | VMware vCenter Server Appliance updates address sensitive information disclosure vulnerability in backup and restore functions (CVE-2019-5537, CVE-2019-5538) | Issue Date | 2019-10-24 | Updated On | 2019-10-24 (Initial Advisory) | CVE(s) | CVE-2019-5537, CVE-2019-5538 VMware vCenter Server Appliance 2. IntroductionVulnerabilities in the File-Based Backup and Restore functions of vCenter Server Appliance were privately reported to the VMware Security Response Center. Updates are available which allow enablement of strict certificate validation to remediate these vulnerabiliti
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-28
Published