CVE-2019-5532 is an information disclosure vulnerability in VMware vCenter Server versions 6.7.x, 6.5, and 6.0, where credentials for virtual machines deployed via OVF are logged in plain-text. A malicious user with access to these log files could view the root account credentials. This vulnerability has a CVSS score of 7.7 (HIGH), indicating a network-based attack with low complexity, requiring low privileges to achieve high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one media article mentioning the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.0:a:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.0:b:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.0:u1:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.0:u1b:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.