4
CVSSv2

CVE-2019-5533

Published: 29/10/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

In VMware SD-WAN by VeloCloud versions 3.x before 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. Among the information is username, first and last name, phone numbers and e-mail address if present but no other personal data. VMware has evaluated the severity of this issue to be in the moderate severity range with a maximum CVSSv3 base score of 4.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware sd-wan by velocloud

Exploits

VMware VeloCloud versions 330 and 322 suffer from an authorization bypass vulnerability ...