CVE-2021-21972
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- VMware vCenter Server Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-22
מוצרים מושפעים
vmware: cloud foundation; vmware: vcenter server
קישורים
- https://www.vmware.com/security/advisories/VMSA-2021-0002.html Vendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2021-0002.html Vendor Advisory
- http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrar… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrar… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource