CVE-2021-21973mediumunder attackCWE-918

CVE-2021-21973: medium-severity vulnerability in VMware vCenter Server

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 5.3epss 88%
from disclosure to weapon20 days
Published on NVDFeb 24
1st PoC+20d
CISA KEV+376d
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-03-21

Apply updates per vendor instructions.

In short

The vSphere Client contains a flaw that allows attackers to manipulate the server into making unauthorized requests to internal systems, potentially exposing sensitive information. An attacker with network access can exploit this by sending specially crafted requests to vCenter Server.

Technical detail

SSRF vulnerability in vCenter Server plugin due to improper URL validation in the HTML5 vSphere Client. Attackers with network access to port 443 can send malicious POST requests to trigger server-side requests to arbitrary internal resources, resulting in information disclosure. Affected versions: vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n, and vCloud Foundation 4.x before 4.2, 3.x before 3.10.1.2.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.