RULE(RULE ID:711195)

Rule General Information
Release Date: 2017-06-16
Rule Name: Vmware Vsphere Data Protection Command Execution Vulnerability (CVE-2017-4914)
Severity:
CVE ID:
Rule Protection Details
Description: VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Mac OS, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:98939
ExploitDB:42152
SecurityTrackerID:1038617
http://www.vmware.com/security/advisories/VMSA-2017-0010.html
Solutions
The vendor has updated advisory on its official website. Please check it for more information.