Cryptographic issues in vCenter Server - CVE-2015-6932
Published: September 19, 2015 / Updated: August 9, 2020
vCenter Server
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.