CVE-2021-21978
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 99%
from disclosure to weapon832 days
Published on NVDMar 3
1st PoC+832d
metasploitMar 2
VulnCheck+1005d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.
Affected products
n/a · VMware View Plannerpublic PoCs found — 1
vulncheckvulncheck.com/xdb/97f6deb588bbunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.