CVE-2015-4057: Dell Vce Vision Intelligent Operations

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings screen, which allows remote attackers to discover the admin user password by sniffing the network.

Affected products

  • Dell Vce Vision Intelligent Operations: up to and including 2.6.4

Published 2017-02-21. Last modified 2026-06-17.