EXPOSURES › CVE-2021-21973
CVE-2021-21973
HIGH ⌖ ON CISA KEV · EXPLOITEDAttackers exploited an unpatched SSRF vulnerability in VMware vCenter Server to gain persistent remote access and deploy backdoors.
VMware vCenter Server and Cloud Foundation suffered a Server-Side Request Forgery (SSRF) vulnerability due to improper URL validation in a plugin, allowing information disclosure and remote access. DIB organizations must care because unpatched, actively exploited vulnerabilities like this enable persistent backdoors and compromise critical infrastructure. Organizations should ensure all VMware components are patched and monitored for exploitation attempts.
Shame score — The vulnerability was actively exploited in the wild to establish persistent remote access, indicating negligent patching and poor security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |