Sensitive Information Disclosure in VMware vCenter Server Appliance
CVE-2019-5537

5.9MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
28 October 2019

Summary

A vulnerability in VMware vCenter Server Appliance exposes sensitive information due to insufficient certificate validation during File-Based Backup and Restore operations. This allows adversaries positioned as a man-in-the-middle to intercept sensitive data transmitted over FTPS and HTTPS, particularly when backing up data to a target. It is essential for users to ensure proper validations and configurations to mitigate risks associated with this vulnerability.

Affected Version(s)

VMware vCenter Server Appliance VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d)

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.