peter bassill · operator
$ cve CVE-2021-21978 JSON

CVE-2021-21978

9.8
CRITICAL · CVSS 3.1 · EPSS 99% (pctl 100)

Patch early

EPSS 99% — above the 10% action threshold.

Description

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.01% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2021-03-03
Last modified2026-06-17

Affected (1)

VendorProduct
vmwareview planner

References

→ the Explorer  ·  watch your stack  ·  NVD