PT-2017-16201 · Vmware · Vcenter Server+1

Published

2017-06-07

·

Updated

2019-10-03

·

CVE-2017-4917

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware vSphere Data Protection versions 5.5.x through 6.1.x
Description The issue allows plaintext credentials to be obtained because VMware vSphere Data Protection locally stores vCenter Server credentials using reversible encryption.
Recommendations For versions 5.5.x through 6.1.x, consider disabling the storage of vCenter Server credentials or restricting access to the reversible encryption mechanism until a fix is available.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-4917

Affected Products

Vmware Vsphere Data Protection
Vcenter Server