vmware sd-wan-by-velocloud CVE-2019-5533 is a vulnerability in VMware Sd Wan By Velocloud
Published on October 29, 2019

In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. Among the information is username, first and last name, phone numbers and e-mail address if present but no other personal data. VMware has evaluated the severity of this issue to be in the moderate severity range with a maximum CVSSv3 base score of 4.3.

NVD


Products Associated with CVE-2019-5533

Want to know whenever a new CVE is published for VMware Sd Wan By Velocloud? stack.watch will email you.

 

Affected Versions

VMware SD-WAN by VeloCloud Version 3.x prior to 3.3.0 is affected by CVE-2019-5533

Exploit Probability

EPSS
1.11%
Percentile
77.92%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.