peter bassill · operator
$ cve CVE-2021-21998 JSON

CVE-2021-21998

9.8
CRITICAL · CVSS 3.1 · EPSS 10.6% (pctl 96)

Patch early

EPSS 10.6% — above the 10% action threshold.

Description

VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.62% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2021-06-23
Last modified2026-06-17

Affected (1)

VendorProduct
vmwarecarbon black app control

References

→ the Explorer  ·  watch your stack  ·  NVD