CVE-2021-21985KEV Β· OVERDUECWE-20CWE-470CWE-918ssrf

VMware vCenter Server Improper Input Validation Vulnerability

Critical Β· published May 26, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 A malicious actor can seize control with a simple exploit on vSphere Client! Just network access to port 443 is all it takes to launch a devastating attack. πŸ”₯ Think of the Virtual SAN Health Check plug-in as a server's front desk where anyone with network access can walk in and dictate terms β€” no questions asked, no validation checks. It's like letting someone order room service without confirming their identity, opening the door to chaos! An attacker could execute commands with unrestricted privileges, giving them full control over the operating system hosting your vCenter Server. This could lead to data theft, unauthorized changes, and potentially a complete system compromise, leaving your environment in shambles!

Put simply

Think of the Virtual SAN Health Check plug-in as a server's front desk where anyone with network access can walk in and dictate terms β€” no questions asked, no validation checks. It's like letting someone order room service without confirming their identity, opening the door to chaos! This vulnerability arises from a lack of proper input validation in the vSphere Client's Virtual SAN Health Check plug-in, which is enabled by default. Attackers can exploit this flaw via network access to port 443, allowing for remote code execution with elevated privileges.

What to do

An attacker could execute commands with unrestricted privileges, giving them full control over the operating system hosting your vCenter Server. This could lead to data theft, unauthorized changes, and potentially a complete system compromise, leaving your environment in shambles! Patch your vCenter Server to version 7.0 U1c or later to mitigate this vulnerability. Additionally, restrict access to port 443 to trusted networks and review your security policies to ensure a layered defense against potential exploits. You've got this! By following these steps, you'll lock down your environment and keep the villains at bay! πŸ›‘οΈ

The record
Technical detail
CVSS v3.1
9.8 Β· CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99999 Β· 100.0th percentile
Weaknesses
CWE-20 Β· Improper Input Validation; CWE-470 Β· Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection'); CWE-918 Β· Server-Side Request Forgery (SSRF)
Published
2021-05-26T19:15Z
KEV added
2021-11-03 Β· due 2021-11-17
Affected products (53)
ProductVersionsFixed in
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/cloud_foundationβ‰₯ 3.0, < 3.10.2.13.10.2.1
vmware/cloud_foundationβ‰₯ 4.0, < 4.2.14.2.1
References (7)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV β€” remediate by Nov 17
    kev
  • 26 MAY 14:04Z
    The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is…
    cvelistv5