Skip to content
COOEY

EXPOSURES › CVE-2021-22017

CVE-2021-22017

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22017 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

Attackers exploited a directory-traversal flaw in VMware vCenter's Syslog server to gain persistent remote access.

An unauthenticated directory-traversal vulnerability in VMware vCenter's Syslog server allowed attackers to deploy reverse SSH backdoors for persistent remote access. DIB organizations must ensure vCenter is patched and monitored, as this flaw enables lateral movement and long-term compromise of critical infrastructure.

Shame score — A maximum-severity directory-traversal flaw was actively exploited in the wild to establish persistent backdoors, indicating negligent patching and poor threat detection.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized