01642 06 11 11 Arrange Call

X.509 Certificate Verification Bypass in VMware vSphere Data Protection and EMC Avamar

CVE-2014-4632 · MEDIUM

CVE-2014-4632

VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.

Learn more about our Cis Benchmark Audit For Server Software.