Skip to content
COOEY

EXPOSURES › CVE-2021-21973

CVE-2021-21973

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-21973 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

Attackers exploited an unpatched SSRF vulnerability in VMware vCenter Server to gain persistent remote access and deploy backdoors.

VMware vCenter Server and Cloud Foundation suffered a Server-Side Request Forgery (SSRF) vulnerability due to improper URL validation in a plugin, allowing information disclosure and remote access. DIB organizations must care because unpatched, actively exploited vulnerabilities like this enable persistent backdoors and compromise critical infrastructure. Organizations should ensure all VMware components are patched and monitored for exploitation attempts.

Shame score — The vulnerability was actively exploited in the wild to establish persistent remote access, indicating negligent patching and poor security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized