CVE-2017-4914: VMware Vsphere Data Protection

Critical severity, CVSS 9.8. EPSS: 8.8% chance of exploitation in the next 30 days.

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.

Affected products

  • VMware Vsphere Data Protection: version 5.5.1 only; version 5.5.5 only; version 5.5.6 only; version 5.5.7 only; version 5.5.8 only; version 5.5.9 only; …

Published 2017-06-07. Last modified 2026-06-17.