CVE-2016-7456: Critical severity vmware vsphere data protection vulnerability
Published Dec 29, 2016
·Updated
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.
Affected Software
22 affected components
VMware vSphere Data Protection=5.5.1
VMware vSphere Data Protection=5.5.5
VMware vSphere Data Protection=5.5.6
VMware vSphere Data Protection=5.5.7
VMware vSphere Data Protection=5.5.8
VMware vSphere Data Protection=5.5.9
VMware vSphere Data Protection=5.5.10
VMware vSphere Data Protection=5.5.11
VMware vSphere Data Protection=5.8.0
VMware vSphere Data Protection=5.8.1
VMware vSphere Data Protection=5.8.2
VMware vSphere Data Protection=5.8.3
VMware vSphere Data Protection=5.8.4
VMware vSphere Data Protection=6.0.0
VMware vSphere Data Protection=6.0.1
VMware vSphere Data Protection=6.0.2
VMware vSphere Data Protection=6.0.3
VMware vSphere Data Protection=6.0.4
VMware vSphere Data Protection=6.1.0
VMware vSphere Data Protection=6.1.1
VMware vSphere Data Protection=6.1.2
VMware vSphere Data Protection=6.1.3
Event History
Dec 29, 2016
CVE Published
via MITRE·09:02 AM
Data Sourced
via MITRE·09:02 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7456?
CVE-2016-7456 is considered to have a high severity due to the risk of unauthorized SSH access.
2
How do I fix CVE-2016-7456?
To fix CVE-2016-7456, update your VMware vSphere Data Protection to a version not affected by this vulnerability.
3
What versions are affected by CVE-2016-7456?
CVE-2016-7456 affects VMware vSphere Data Protection versions 5.5.x through 6.1.x.
4
Can CVE-2016-7456 be exploited remotely?
Yes, CVE-2016-7456 can be exploited remotely through an SSH session.
5
Is there a workaround for CVE-2016-7456?
While the best solution is to apply updates, limiting SSH access can be a temporary workaround for CVE-2016-7456.