CVE-2021-22017
בינונית 5.3 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- VMware vCenter Server Improper Access Control
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 49% (אחוזון 100) נכון ל-25/7/2026
מוצרים מושפעים
vmware: vcenter server
קישורים
- https://www.vmware.com/security/advisories/VMSA-2021-0020.html PatchVendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2021-0020.html PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource