Information disclosure in vCenter Server Appliance - CVE-2019-5537
Published: October 30, 2019 / Updated: October 31, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a lack of certificate validation during the File-Based Backup and Restore operations. A remote attacker with man-in-the-middle positioning between vCenter Server Appliance and a backup target can intercept sensitive data in transit over FTPS and HTTPS and gain unauthorized access to sensitive information on the system.
Affected software
VCF over VxRail
Dell EMC VxRail Appliance
How to mitigate CVE-2019-5537
VCF over VxRail - update to 3.9.1
Dell EMC VxRail Appliance - addressed in versions 4.5.401, 4.7.301