Showing 2 vulnerabilities on this page for vSphere Data Protection (VDP)

Signals CISA KEV Ransomware Nuclei
VMware vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.

CWE-327Jun 7, 2017
CVSS9.8v3.0EPSS0.842%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

VMware vSphere Data Protection 5.x/6.x - Java Deserialization

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.

CWE-502Jun 7, 2017
CVSS9.8v3.0EPSS8.83%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX