« Back to list

CVE-2016-7456

Status: ModifiedCritical (9.8)—

VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2016-7456",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-12-29T09:59:00.540",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/94990",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1037502",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2016-0024.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/94990",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1037502",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2016-0024.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session."
    },
    {
      "lang": "es",
      "value": "VMware vSphere Data Protection (VDP) 5.5.x hasta la versión 6.1.x tiene una clave privada SSH con una contraseña públicamente conocida, lo que hace más fácil a atacantes remotos obtener acceso de inicio de sesión a través de una sesión SSH."
    }
  ],
  "lastModified": "2026-06-17T00:53:06.093",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC2725FD-0BEF-442B-A2D6-83C1BF3644E5"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "785AF64D-7D94-49C2-9590-54C709736136"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A8679C1-4ACA-4E6C-90FC-C906C6E70AA4"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.5.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43F7F343-0BC4-4142-8FEF-3F52A1AD6EEE"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.5.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5455D69B-3439-4345-956F-EB7F80D8AFED"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.5.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E49E8B4D-B20A-42F5-BDAF-A53459E980BA"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.5.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2ABC25F6-3793-475A-A4AA-B52CA0B6AFC7"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.5.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE870CC9-2B3B-4C80-AB92-A0F1CB869BA8"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "333C262E-9FB0-4A7B-8269-D58FA1371679"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCB9A697-E4F7-4A8E-BFCC-ACC33EEFF33C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2438674B-8D7C-433A-A7F1-E97A546DC3D8"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05828BD4-C209-4278-80DF-632274B2ECBD"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:5.8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59A07628-0466-4E91-B016-4C6B311C479E"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBA48F5F-3B72-427E-9C9A-E5C3EC03A5F8"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AF32F55-AE25-4F52-B043-1C2623344F1A"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8FEBFF6-CEF2-4A8E-BA29-3F383D6DF436"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEC123DA-FBC3-4075-B4C0-A5295A6965A1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D8E9053-F846-48A5-93D7-35D0665D4038"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D7E39A9-BE37-4848-BAD2-7F97D04F0D7C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A908399-8C17-46B6-B554-77F588C2BF42"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC8AFC55-915D-46AC-80DA-E100F4CFFD64"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vsphere_data_protection:6.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2B9A334-69EB-4E88-A446-18A1B0C669B2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}