CVE-2014-4632
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.
vSphere Data Protection (VDP) versión 5.1, versiones 5.5 anteriores a 5.5.9 y versiones 5.8 anteriores a 5.8.1 de VMware y el cliente proxy en Avamar Data Store (ADS) y Avamar Virtual Edition (AVE) versiones 6.x y 7.0.x de EMC, no comprueba apropiadamente los certificados X.509 de los servidores SSL de vCenter Server, lo que permite atacantes de tipo man-in-the-middle falsificar servidores, y omitir las restricciones de acceso de copia de seguridad y restauración previstas, por medio de un certificado diseñado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-06-24 CVE Reserved
- 2015-01-30 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2015-01/0154.html | Mailing List | |
http://www.securitytracker.com/id/1031664 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100866 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.vmware.com/security/advisories/VMSA-2015-0002.html | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Vsphere Data Protection Search vendor "Vmware" for product "Vsphere Data Protection" | 5.1 Search vendor "Vmware" for product "Vsphere Data Protection" and version "5.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vsphere Data Protection Search vendor "Vmware" for product "Vsphere Data Protection" | 5.5.1 Search vendor "Vmware" for product "Vsphere Data Protection" and version "5.5.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vsphere Data Protection Search vendor "Vmware" for product "Vsphere Data Protection" | 5.5.6 Search vendor "Vmware" for product "Vsphere Data Protection" and version "5.5.6" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vsphere Data Protection Search vendor "Vmware" for product "Vsphere Data Protection" | 5.5.7 Search vendor "Vmware" for product "Vsphere Data Protection" and version "5.5.7" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vsphere Data Protection Search vendor "Vmware" for product "Vsphere Data Protection" | 5.5.8 Search vendor "Vmware" for product "Vsphere Data Protection" and version "5.5.8" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vsphere Data Protection Search vendor "Vmware" for product "Vsphere Data Protection" | 5.8.0 Search vendor "Vmware" for product "Vsphere Data Protection" and version "5.8.0" | - |
Affected
|