94990vdb entry
http://www.securityfocus.com/bid/94990 CVE-2016-7456
CRITICAL
VMware VDP Known SSH Key
Record summary
CVE-2016-7456 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitVMware VDP Known SSH KeyMetasploit exploitby phroxvsNot analyzed1 file
References
41037502vdb entry
http://www.securitytracker.com/id/1037502 vmware.comConfirmation
http://www.vmware.com/security/advisories/VMSA-2016-0024.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-7456