Cleartext Transmission Vulnerability in VMware vCenter Plug-in
CVE-2015-4057
7.5HIGH
What is CVE-2015-4057?
The VCE Vision Intelligent Operations plug-in for VMware vCenter is vulnerable due to improper handling of HTTP responses. Specifically, prior to version 2.6.5, it transmits sensitive information, including admin user credentials, in cleartext over the network when accessing the Settings screen. This design flaw allows remote attackers to intercept these transmissions and easily compromise administrator accounts by sniffing the network traffic, leading to unauthorized access and potential system compromise.