Cleartext Transmission Vulnerability in VMware vCenter Plug-in
CVE-2015-4057
7.5HIGH
Summary
The VCE Vision Intelligent Operations plug-in for VMware vCenter is vulnerable due to improper handling of HTTP responses. Specifically, prior to version 2.6.5, it transmits sensitive information, including admin user credentials, in cleartext over the network when accessing the Settings screen. This design flaw allows remote attackers to intercept these transmissions and easily compromise administrator accounts by sniffing the network traffic, leading to unauthorized access and potential system compromise.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved