CVE-2017-4917: VMware Vsphere Data Protection
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
Affected products
- VMware Vsphere Data Protection: version 5.5.5 only; version 5.5.6 only; version 5.5.7 only; version 5.5.8 only; version 5.5.9 only; version 5.5.10 only; …
Published 2017-06-07. Last modified 2026-06-17.