peter bassill · operator
$ cve CVE-2021-21973 JSON

CVE-2021-21973 KEV

5.3
MEDIUM · CVSS 3.1 · EPSS 87.6% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-21.

Description

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS87.64% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-918
On CISA KEVyes — remediate by 2022-03-21
Public exploitnone known
Published2021-02-24
Last modified2026-06-17

CISA KEV

NameVMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
Added2022-03-07
Due2022-03-21
Vendor / productVMware / vCenter Server and Cloud Foundation
Ransomware usenone reported

Affected (2)

VendorProduct
vmwarecloud foundation
vmwarevcenter server

References

→ the Explorer  ·  watch your stack  ·  NVD