Information disclosure in vCenter Server - CVE-2017-4923

 

Information disclosure in vCenter Server - CVE-2017-4923

Published: August 1, 2017


Vulnerability identifier: #VU7641
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-4923
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: VMware, Inc
Affected software:
vCenter Server

Detailed vulnerability description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to improper security restrictions that are set on the vCenter Server Appliance file-based backup feature. A remote attacker can use the file-based backup feature to access important data, such as plaintext credentials, that may be used to conduct further attack.

Successful exploitation of the vulnerability results in information disclosure.


How to mitigate CVE-2017-4923

Update to version 6.5 U1.

Sources