4.3
CVE-2014-4632
- EPSS 0.14%
- Published 01.02.2015 02:59:00
- Last modified 12.04.2025 10:46:40
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.
Data is provided by the National Vulnerability Database (NVD)
VMware ≫ Vsphere Data Protection Version5.1
VMware ≫ Vsphere Data Protection Version5.5.1
VMware ≫ Vsphere Data Protection Version5.5.6
VMware ≫ Vsphere Data Protection Version5.5.7
VMware ≫ Vsphere Data Protection Version5.5.8
VMware ≫ Vsphere Data Protection Version5.8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.14% | 0.311 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|