Sensitive Information Disclosure in VMware vCenter Server Appliance
CVE-2019-5537
5.9MEDIUM
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 28 October 2019
Summary
A vulnerability in VMware vCenter Server Appliance exposes sensitive information due to insufficient certificate validation during File-Based Backup and Restore operations. This allows adversaries positioned as a man-in-the-middle to intercept sensitive data transmitted over FTPS and HTTPS, particularly when backing up data to a target. It is essential for users to ensure proper validations and configurations to mitigate risks associated with this vulnerability.
Affected Version(s)
VMware vCenter Server Appliance VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d)
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved