Cleartext Transmission Vulnerability in VMware vCenter Plug-in
CVE-2015-4057

7.5HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
21 February 2017

Summary

The VCE Vision Intelligent Operations plug-in for VMware vCenter is vulnerable due to improper handling of HTTP responses. Specifically, prior to version 2.6.5, it transmits sensitive information, including admin user credentials, in cleartext over the network when accessing the Settings screen. This design flaw allows remote attackers to intercept these transmissions and easily compromise administrator accounts by sniffing the network traffic, leading to unauthorized access and potential system compromise.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.