Information disclosure in vCenter Server Appliance - CVE-2019-5538
Published: October 30, 2019 / Updated: October 31, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a lack of certificate validation during the File-Based Backup and Restore operations. A remote attacker with man-in-the-middle positioning between vCenter Server Appliance and a backup target can intercept sensitive data in transit over SCP and gain unauthorized access to sensitive information on the system.
Affected software
VCF over VxRail
Dell EMC VxRail Appliance
How to mitigate CVE-2019-5538
VCF over VxRail - update to 3.9.1
Dell EMC VxRail Appliance - addressed in versions 4.5.401, 4.7.301