This CPE summary could be partial or incomplete. Please contact us for a detailed listing.


Vendor Vmware First view 2015-01-31
Product Vsphere Data Protection Last view 2015-01-31
Version 5.1 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
CPE Product cpe:2.3:a:vmware:vsphere_data_protection

Activity : Overall

Related : CVE

  Date Alert Description
4.3 2015-01-31 CVE-2014-4632

VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.

CWE : Common Weakness Enumeration

100% (1) CWE-310 Cryptographic Issues

Information Assurance Vulnerability Management (IAVM)

id Description
2015-B-0016 VMware vSphere Data Protection Certificate Validation Security Bypass Vulnera...
Severity: Category II - VMSKEY: V0058529

Nessus® Vulnerability Scanner

id Description
2015-02-12 Name: The remote host has a virtualization appliance installed that is affected by ...
File: vmware_vsphere_data_protection_vmsa-2015-0002.nasl - Type: ACT_GATHER_INFO