← Vulnerability feed

Vulnerability record · CVE-2017-4914 · published 7 June 2017

CVE-2017-4914: Vmware vsphere data protection deserialization of untrusted data vulnerability

Vmware · Vsphere Data Protection

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.

9.8 CVSS 3.0 Critical EPSS 8.8% · top 5.0% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.0 base score, v2 7.5
8.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-4914 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-11066Dell emc avamar vulnerabilityDell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrate…EPSS 9.9%9.8CVE-2017-4917Vmware vsphere data protection broken cryptographic algorithm vulnerabilityVMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue…EPSS 0.84%9.8CVE-2016-7456Vmware vsphere data protection vulnerabilityVMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attac…EPSS 33%6.7CVE-2018-11077Dell emc avamar os command injection vulnerability'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Pro…EPSS 1.0%6.5CVE-2018-11076Dell emc avamar vulnerabilityDell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected…EPSS 0.83%6.1CVE-2018-11067Dell emc avamar open redirect vulnerabilityDell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrate…EPSS 1.8%4.3CVE-2014-4632Vmware vsphere data protection vulnerabilityVMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtu…EPSS 0.62%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2017-4914), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.