peter bassill · operator
$ cve CVE-2021-21985 JSON

CVE-2021-21985 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2021-11-17.

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-918
On CISA KEVyes — remediate by 2021-11-17
Public exploitnone known
Published2021-05-26
Last modified2026-08-12

CISA KEV

NameVMware vCenter Server Improper Input Validation Vulnerability
Added2021-11-03
Due2021-11-17
Vendor / productVMware / vCenter Server
Ransomware useknown

Affected (2)

VendorProduct
vmwarecloud foundation
vmwarevcenter server

References

→ the Explorer  ·  watch your stack  ·  NVD