CISA KEV · Known exploitedMedium

CVE-2021-21973

VMware vCenter Server and Cloud Foundation

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

CVSS
5.3
EPSS
88.0%
99.8% percentile
CISA KEV
Listed
Published
2021.02.25
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability88.0%
Technical severityCVSS 5.3

Vulnerability overview

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Affected product and versions

Product
VMware vCenter Server and Cloud Foundation
Affected versions
7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n, 4.x before 4.2, 3.x before 3.10.1.2, >= 3.0 < 3.10.1.2, >= 4.0 < 4.2, 6.5, 6.7, 7.0
Fixed versions
3.10.1.2, 4.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply updates per vendor instructions.

Due date: 2022.03.21
  1. 1
    Identify

    Confirm that VMware vCenter Server and Cloud Foundation and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE
CWE-20, CWE-918
KEV added
2022.03.07
Ransomware use
미확인
CVE-2021-21973 — VMware vCenter Server and Cloud Foundation | SECUFOCUS NOW