CVE-2021-22005
Description
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
Summary dbcve.org
CVE-2021-22005 is a critical arbitrary file upload vulnerability in the VMware vCenter Server Analytics service. An unauthenticated attacker with network access to port 443 can upload a specially crafted file and achieve remote code execution on the vCenter Server. This vulnerability has a CVSS score of 9.8 due to the trivial exploitability combined with the high-value target nature of vCenter Server.
Mitigation
Apply the VMware security patch for CVE-2021-22005 immediately; versions 7.0 and 8.0 received patches in the October 2021 security advisory. Until patched, restrict network access to vCenter Server port 443 and monitor for indicators of compromise.