Vulnerabilities > CVE-2014-4632 - Cryptographic Issues vulnerability in VMWare Vsphere Data Protection
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Signature Spoofing by Key Recreation An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
Nessus
NASL family | Misc. |
NASL id | VMWARE_VSPHERE_DATA_PROTECTION_VMSA-2015-0002.NASL |
description | The version of VMware vSphere Data Protection installed on the remote host is 5.1.x / 5.5.x prior to 5.5.9, or 5.8.x prior to 5.8.1. It is, therefore, affected by a certificate validation vulnerability that allows man-in-the-middle (MitM) attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 81315 |
published | 2015-02-12 |
reporter | This script is Copyright (C) 2015-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/81315 |
title | VMware vSphere Data Protection Certificate Validation (VMSA-2015-0002) |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2015-01/0154.html
- http://archives.neohapsis.com/archives/bugtraq/2015-01/0154.html
- http://www.securitytracker.com/id/1031664
- http://www.securitytracker.com/id/1031664
- http://www.vmware.com/security/advisories/VMSA-2015-0002.html
- http://www.vmware.com/security/advisories/VMSA-2015-0002.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100866
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100866