EXPOSURES › CVE-2021-22017
CVE-2021-22017
HIGH ⌖ ON CISA KEV · EXPLOITEDAttackers exploited a directory-traversal flaw in VMware vCenter's Syslog server to gain persistent remote access.
An unauthenticated directory-traversal vulnerability in VMware vCenter's Syslog server allowed attackers to deploy reverse SSH backdoors for persistent remote access. DIB organizations must ensure vCenter is patched and monitored, as this flaw enables lateral movement and long-term compromise of critical infrastructure.
Shame score — A maximum-severity directory-traversal flaw was actively exploited in the wild to establish persistent backdoors, indicating negligent patching and poor threat detection.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |