SB2015020101 - Cryptographic issues in VMware, vSphere Data Protection



SB2015020101 - Cryptographic issues in VMware, vSphere Data Protection

Published: February 1, 2015 Updated: August 9, 2020

Security Bulletin ID SB2015020101
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cryptographic issues (CVE-ID: CVE-2014-4632)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.


Remediation

Install update from vendor's website.