CRITICAL

CVE-2021-22005

Vmware Cloud Foundation 2021-09-23 CVSS v3.1
CVSS
9.8
KEV

Description

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

Summary dbcve.org

CVE-2021-22005 is a critical arbitrary file upload vulnerability in the VMware vCenter Server Analytics service. An unauthenticated attacker with network access to port 443 can upload a specially crafted file and achieve remote code execution on the vCenter Server. This vulnerability has a CVSS score of 9.8 due to the trivial exploitability combined with the high-value target nature of vCenter Server.

Mitigation

Apply the VMware security patch for CVE-2021-22005 immediately; versions 7.0 and 8.0 received patches in the October 2021 security advisory. Until patched, restrict network access to vCenter Server port 443 and monitor for indicators of compromise.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE