CVE-2014-4632: Medium severity vmware vsphere data protection vulnerability
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4632?
CVE-2014-4632 is rated as a critical vulnerability due to potential exposure to man-in-the-middle attacks.
How do I fix CVE-2014-4632?
To fix CVE-2014-4632, upgrade to VMware vSphere Data Protection versions 5.5.9 or 5.8.1 or later.
Which versions of VMware vSphere Data Protection are affected by CVE-2014-4632?
CVE-2014-4632 affects VMware vSphere Data Protection versions 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1.
Does CVE-2014-4632 affect EMC Avamar Data Store?
Yes, CVE-2014-4632 also affects EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 6.x and 7.0.x.
What type of attack does CVE-2014-4632 enable?
CVE-2014-4632 enables man-in-the-middle attacks due to improper verification of X.509 certificates.