Information disclosure in vCenter Server - CVE-2017-4923

 

Information disclosure in vCenter Server - CVE-2017-4923

Published: August 1, 2017


Vulnerability identifier: #VU7641
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-4923
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to improper security restrictions that are set on the vCenter Server Appliance file-based backup feature. A remote attacker can use the file-based backup feature to access important data, such as plaintext credentials, that may be used to conduct further attack.

Successful exploitation of the vulnerability results in information disclosure.


Affected software

vCenter Server

How to mitigate CVE-2017-4923

Update to version 6.5 U1.


External References

Related Security Bulletins