
====================================================================

                                CERT-Renater

                    Note d'Information No. 2016/VULN419
_____________________________________________________________________

DATE                : 21/12/2016

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running vSphere Data Protection versions
                              6.1.x, 6.0.x, 5.8.x, 5.5.x.

=====================================================================
http://www.vmware.com/security/advisories/VMSA-2016-0024.html
____________________________________________________________________

- --------------------------------------------------------------------------
                         VMware Security Advisory

Advisory ID: VMSA-2016-0024
Severity:    Critical
Synopsis:    vSphere Data Protection (VDP) updates address SSH Key-Based
              authentication issue
Issue date:  2016-12-20
Updated on:  2016-12-20 (Initial Advisory)
CVE number:  CVE-2016-7456

1. Summary

    vSphere Data Protection (VDP) updates address SSH key-based
    authentication issue

2. Relevant Products

    vSphere Data Protection (VDP)

3. Problem Description

    a. VDP SSH key-based authentication issue

    VDP contains a private SSH key with a known password that is
    configured to allow key-based authentication. Exploitation of this
    issue may allow an unauthorized remote attacker to log into the
    appliance with root privileges.

    VMware would like to thank Marc Ströbel aka phroxvs from
    HvS-Consulting for reporting this issue to VMware.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the identifier CVE-2016-7456 to this issue.

    Column 5 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware      Product    Running            Replace with/     Mitigation/
    Product     Version    on       Severity  Apply Patch       Workaround
    ==========  =========  =======  ========  ================  ==========
    VDP         6.1.x      VA       Critical  KB2147069         None
    VDP         6.0.x      VA       Critical  KB2147069         None
    VDP         5.8.x      VA       Critical  KB2147069         None
    VDP         5.5.x      VA       Critical  KB2147069         None

4. Solution

    Please review the patch/release notes for your product and version
    and verify the checksum of your downloaded file.

    vSphere Data Protection
    Downloads and Documentation:
    http://kb.vmware.com/kb/2147069

5. References

    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7456

- --------------------------------------------------------------------------

6. Change log

    2016-12-20: VMSA-2016-0024
    Initial security advisory in conjunction with the release of vSphere
    Data Protection updates on 2016-12-20.

- --------------------------------------------------------------------------

7. Contact

    E-mail list for product security notifications and announcements:
    http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce

    This Security Advisory is posted to the following lists:

     security-announce@lists.vmware.com
     bugtraq@securityfocus.com
     fulldisclosure@seclists.org

    E-mail: security at vmware.com
    PGP key at: https://kb.vmware.com/kb/1055

    VMware Security Advisories
    http://www.vmware.com/security/advisories

    VMware Security Response Policy
    https://www.vmware.com/support/policies/security_response.html

    VMware Lifecycle Support Phases
    https://www.vmware.com/support/policies/lifecycle.html
    Twitter
    https://twitter.com/VMwareSRC

    Copyright 2016 VMware Inc.  All rights reserved.

==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================




