VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVMware vSphere Data Protection
APPVmware5.5.105.5.115.5.55.5.65.5.75.5.85.5.95.8.05.8.15.8.25.8.35.8.46.0.06.0.16.0.2+ 6 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2018-11066CRITICAL9.8PL ✓same product
RCE w Dell EMC Avamar Client Manager — zdalny dostęp bez uwierzytelnienia
CVE-2017-4914CRITICAL9.8PL ✓same product
Zdalne wykonanie kodu przez błąd deserializacji w VMware vSphere Data Protection
CVE-2016-7456CRITICAL9.8PL ✓same product
VMware vSphere Data Protection — znany klucz SSH umożliwia zdalny dostęp
CVE-2018-11067MEDIUM6.1same product
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7....
CVE-2018-11076MEDIUM6.5same product
Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Prote...