CVE-2017-4917: Critical severity vmware vsphere data protection vulnerability
Published Jun 7, 2017
·Updated
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
Affected Software
21 affected components
VMware vSphere Data Protection=5.5.5
VMware vSphere Data Protection=5.5.6
VMware vSphere Data Protection=5.5.7
VMware vSphere Data Protection=5.5.8
VMware vSphere Data Protection=5.5.9
VMware vSphere Data Protection=5.5.10
VMware vSphere Data Protection=5.5.11
VMware vSphere Data Protection=5.8.0
VMware vSphere Data Protection=5.8.1
VMware vSphere Data Protection=5.8.2
VMware vSphere Data Protection=5.8.3
VMware vSphere Data Protection=5.8.4
VMware vSphere Data Protection=6.0.0
VMware vSphere Data Protection=6.0.1
VMware vSphere Data Protection=6.0.2
VMware vSphere Data Protection=6.0.3
VMware vSphere Data Protection=6.0.4
VMware vSphere Data Protection=6.1.0
VMware vSphere Data Protection=6.1.1
VMware vSphere Data Protection=6.1.2
VMware vSphere Data Protection=6.1.3
Remediation
Event History
Jun 7, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-4917?
CVE-2017-4917 is rated as a high severity vulnerability.
2
How do I fix CVE-2017-4917?
To fix CVE-2017-4917, update your VMware vSphere Data Protection to a patched version as recommended by VMware.
3
What impact does CVE-2017-4917 have on my system?
CVE-2017-4917 may allow an attacker to obtain plaintext vCenter Server credentials, compromising the system's security.
4
Which versions of VMware are affected by CVE-2017-4917?
CVE-2017-4917 affects VMware vSphere Data Protection versions 5.5.x, 5.8.x, and 6.0.x to 6.1.x.
5
Is CVE-2017-4917 a remote or local vulnerability?
CVE-2017-4917 is considered a local vulnerability since it involves access to stored credentials on the same system.