Lucene search

K
nvd[email protected]NVD:CVE-2019-5532
HistorySep 18, 2019 - 9:15 p.m.

CVE-2019-5532

2019-09-1821:15:13
CWE-532
web.nvd.nist.gov
1

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

7.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.2%

VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).

Affected configurations

NVD
Node
vmwarevcenter_serverMatch6.0
OR
vmwarevcenter_serverMatch6.0a
OR
vmwarevcenter_serverMatch6.0b
OR
vmwarevcenter_serverMatch6.0u1
OR
vmwarevcenter_serverMatch6.0u1b
OR
vmwarevcenter_serverMatch6.0u3
OR
vmwarevcenter_serverMatch6.0update2
OR
vmwarevcenter_serverMatch6.0update2a
OR
vmwarevcenter_serverMatch6.0update2m
OR
vmwarevcenter_serverMatch6.0update3a
OR
vmwarevcenter_serverMatch6.0update3b
OR
vmwarevcenter_serverMatch6.0update3c
OR
vmwarevcenter_serverMatch6.0update3d
OR
vmwarevcenter_serverMatch6.0update3e
OR
vmwarevcenter_serverMatch6.0update3f
OR
vmwarevcenter_serverMatch6.0update3g
OR
vmwarevcenter_serverMatch6.0update3h
OR
vmwarevcenter_serverMatch6.0update3i
Node
vmwarevcenter_serverMatch6.7
OR
vmwarevcenter_serverMatch6.7a
OR
vmwarevcenter_serverMatch6.7b
OR
vmwarevcenter_serverMatch6.7c
OR
vmwarevcenter_serverMatch6.7d
OR
vmwarevcenter_serverMatch6.7update1
OR
vmwarevcenter_serverMatch6.7update1b
OR
vmwarevcenter_serverMatch6.7update2
OR
vmwarevcenter_serverMatch6.7update2a
OR
vmwarevcenter_serverMatch6.7update2c
Node
vmwarevcenter_serverMatch6.5
OR
vmwarevcenter_serverMatch6.5a
OR
vmwarevcenter_serverMatch6.5b
OR
vmwarevcenter_serverMatch6.5c
OR
vmwarevcenter_serverMatch6.5d
OR
vmwarevcenter_serverMatch6.5update1
OR
vmwarevcenter_serverMatch6.5update1b
OR
vmwarevcenter_serverMatch6.5update1c
OR
vmwarevcenter_serverMatch6.5update1d
OR
vmwarevcenter_serverMatch6.5update1e
OR
vmwarevcenter_serverMatch6.5update1g
OR
vmwarevcenter_serverMatch6.5update2
OR
vmwarevcenter_serverMatch6.5update2b
OR
vmwarevcenter_serverMatch6.5update2c
OR
vmwarevcenter_serverMatch6.5update2d
OR
vmwarevcenter_serverMatch6.5update2g

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

7.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.2%

Related for NVD:CVE-2019-5532