Vmware Vsphere Data Protection vulnerabilities

8 known vulnerabilities affecting vmware/vsphere_data_protection.

Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2018-11066CRITICALCVSS 9.8v6.0.0v6.0.1+17 more2018-11-26
CVE-2018-11066 [CRITICAL] CVE-2018-11066: Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary
nvd
CVE-2018-11077MEDIUMCVSS 6.7v6.0.0v6.0.1+17 more2018-11-26
CVE-2018-11077 [MEDIUM] CWE-78 CVE-2018-11077: 'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0 'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root pri
nvd
CVE-2018-11076MEDIUMCVSS 6.5v6.0.0v6.0.1+17 more2018-11-26
CVE-2018-11076 [MEDIUM] CVE-2018-11076: Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private key could potentially be used by an unauthe
nvd
CVE-2018-11067MEDIUMCVSS 6.1v6.0.0v6.0.1+17 more2018-11-26
CVE-2018-11067 [MEDIUM] CWE-601 CVE-2018-11067: Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect applica
nvd
CVE-2017-4914CRITICALCVSS 9.8PoCv5.5.1v5.5.5+20 more2017-06-07
CVE-2017-4914 [CRITICAL] CWE-502 CVE-2017-4914: VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
nvd
CVE-2017-4917CRITICALCVSS 9.8v5.5.5v5.5.6+19 more2017-06-07
CVE-2017-4917 [CRITICAL] CWE-327 CVE-2017-4917: VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server cr VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
nvd
CVE-2016-7456CRITICALCVSS 9.8v5.5.1v5.5.5+20 more2016-12-29
CVE-2016-7456 [CRITICAL] CWE-255 CVE-2016-7456: VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.
nvd
CVE-2014-4632MEDIUMCVSS 4.3v5.1v5.5.1+4 more2015-02-01
CVE-2014-4632 [MEDIUM] CWE-310 CVE-2014-4632: VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy clien VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore
nvd
Vmware Vsphere Data Protection vulnerabilities | cvebase