CVE-2016-7456: VMware Vsphere Data Protection

Critical severity, CVSS 9.8. EPSS: 32.8% chance of exploitation in the next 30 days.

VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.

Affected products

  • VMware Vsphere Data Protection: version 5.5.1 only; version 5.5.5 only; version 5.5.6 only; version 5.5.7 only; version 5.5.8 only; version 5.5.9 only; …

Published 2016-12-29. Last modified 2026-06-17.